๐Ÿ” CVE Alert

CVE-2026-55060

LOW 3.7

GoCD is vulnerable to authorization bypass via support process list API

CVSS Score
3.7
EPSS Score
0.0%
EPSS Percentile
0th

GoCD is a continuous deliver server. From 13.1.0 until 26.1.0, the /go/api/support/process_list endpoint does not enforce its intended administrator-only authorization. An authenticated internal user can query the endpoint while source control child processes are running and view command-line arguments, usernames, remote material URLs, and internal material paths for materials the user cannot otherwise access. Exploitation depends on unpredictable process timing, and credentials, environment variables, and user-defined secrets remain masked or omitted. This issue is fixed in version 26.1.0.

CWE CWE-863
Vendor gocd
Product gocd
Published Sep 21, 2026
Stay Ahead of the Next One

Get instant alerts for gocd gocd

Be the first to know when new low vulnerabilities affecting gocd gocd are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

gocd / gocd
>= 13.1.0, < 26.1.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/gocd/gocd/security/advisories/GHSA-vqjf-7pf8-hgwr github.com: https://github.com/gocd/gocd/commit/fbf832f9358d96466bb87fad11a1de0ba935fea8 github.com: https://github.com/gocd/gocd/releases/tag/26.1.0 gocd.org: https://www.gocd.org/releases/#26-1-0