๐Ÿ” CVE Alert

CVE-2026-52742

UNKNOWN 0.0

GoCD is vulnerable to historical server configuration API authorization bypass

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

GoCD is a continuous deliver server. From 12.3.1 until 26.1.0, legacy routes under /go/admin/restful/* expose historical full server configuration to pipeline group administrators instead of restricting responses to configuration for groups they administer. The disclosed configuration can include agent auto-registration keys, webhook invocation keys, encrypted material credentials, and GoCD administrator lists. A malicious pipeline group administrator can use disclosed agent registration data to connect a rogue compatible agent, which can create a higher-complexity path to receiving work or overwriting artifacts associated with other groups. Normal authenticated users are not affected, the endpoint does not modify server configuration, and deployments that restrict pipeline editing to full administrators or configuration repositories are not affected. This issue is fixed in version 26.1.0.

CWE CWE-863
Vendor gocd
Product gocd
Published Sep 21, 2026
Last Updated Sep 21, 2026
Stay Ahead of the Next One

Get instant alerts for gocd gocd

Be the first to know when new unknown vulnerabilities affecting gocd gocd are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

gocd / gocd
>= 12.3.1, < 26.1.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/gocd/gocd/security/advisories/GHSA-7xxx-fv46-vp7h github.com: https://github.com/gocd/gocd/pull/14398 github.com: https://github.com/gocd/gocd/commit/8be3a674c3434fa6aa772d7c22fb7b0277950cd7 github.com: https://github.com/gocd/gocd/releases/tag/26.1.0 gocd.org: https://www.gocd.org/releases/#26-1-0