PT-2026-96135 · Gocd · Gocd

CVE-2026-55870

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v4.0

2.3

Low

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions GoCD versions prior to 26.1.0
Description GoCD can return unmasked credentials stored in the userinfo portion of source control material URLs. This occurs through several read-only APIs available to regular authenticated users. While dedicated password fields remain encrypted, legacy configurations that permit credentials within material URLs may not be consistently masked across all mixed-use APIs for every material type. Consequently, an authenticated user with access to an affected pipeline can obtain these embedded credentials.
Recommendations Update to version 26.1.0. Avoid storing credentials in the userinfo portion of source control material URLs and use dedicated username and password fields or secret-management plugins instead.

Exploit

Fix

Information Disclosure

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55870
GHSA-5M25-5J77-C887

Affected Products

Gocd