CVE-2026-52743Medium· 4.3▾ SunlitGoCD is a continuous deliver server. Prior to 26.1.0, the internal GoCD UI /jobStatus.json API does not validate that a requested server-assigned job ID belongs to the pipeline and stage named in the request. An authenticated user can gu…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
GoCD is a continuous deliver server. Prior to 26.1.0, the internal GoCD UI /jobStatus.json API does not validate that a requested server-assigned job ID belongs to the pipeline and stage named in the request. An authenticated user can guess job IDs and retrieve status for jobs in pipelines the user cannot otherwise view, including job names, state, progress timestamps, assigned agent IP addresses and UUIDs, and associated stages and pipelines. The response does not expose console output, artifacts, commands, variables, or configuration. This issue is fixed in version 26.1.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55060Low· 3.7GoCD is a continuous deliver server
CVE-2026-52742Medium· 5.1GoCD is a continuous deliver server
CVE-2026-52740Medium· 5.3GoCD is a continuous deliver server
CVE-2026-68919High· 7.0GoCD is a continuous deliver server
CVE-2026-52741High· 7.5GoCD is a continuous deliver server
CVE-2026-15630Critical· 9.9CVE-2026-15630