CVE-2026-52744
GoCD is vulnerable to authorization bypass via fetch artifact autosuggestion API
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal GoCD UI fetch-artifact auto-suggestion API at /go/api/internal/pipelines/**/upstream does not adequately authorize access to upstream dependency data. An authenticated user can retrieve inter-pipeline dependency hierarchy details and user-defined pipeline, stage, job, and artifact plugin reference names that the user cannot otherwise view in the UI. The endpoint is read-only and does not permit modification of pipeline data. This issue is fixed in version 26.1.0.
| CWE | CWE-862 |
| Vendor | gocd |
| Product | gocd |
| Published | Sep 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for gocd gocd
Be the first to know when new unknown vulnerabilities affecting gocd gocd are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
gocd / gocd
>= 20.2.0, < 26.1.0