๐Ÿ” CVE Alert

CVE-2026-52744

UNKNOWN 0.0

GoCD is vulnerable to authorization bypass via fetch artifact autosuggestion API

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal GoCD UI fetch-artifact auto-suggestion API at /go/api/internal/pipelines/**/upstream does not adequately authorize access to upstream dependency data. An authenticated user can retrieve inter-pipeline dependency hierarchy details and user-defined pipeline, stage, job, and artifact plugin reference names that the user cannot otherwise view in the UI. The endpoint is read-only and does not permit modification of pipeline data. This issue is fixed in version 26.1.0.

CWE CWE-862
Vendor gocd
Product gocd
Published Sep 23, 2026
Stay Ahead of the Next One

Get instant alerts for gocd gocd

Be the first to know when new unknown vulnerabilities affecting gocd gocd are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

gocd / gocd
>= 20.2.0, < 26.1.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/gocd/gocd/security/advisories/GHSA-mvpm-hmc9-2q8p github.com: https://github.com/gocd/gocd/commit/ce9602d7bb27dcb89bf8fc15eb859306cdc8995c github.com: https://github.com/gocd/gocd/releases/tag/26.1.0 gocd.org: https://www.gocd.org/releases/#26-1-0