CVE-2026-52744Medium· 5.3▾ SunlitGoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal GoCD UI fetch-artifact auto-suggestion API at /go/api/internal/pipelines/**/upstream does not adequately authorize access to upstream dependency data. An authent…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal GoCD UI fetch-artifact auto-suggestion API at /go/api/internal/pipelines/**/upstream does not adequately authorize access to upstream dependency data. An authenticated user can retrieve inter-pipeline dependency hierarchy details and user-defined pipeline, stage, job, and artifact plugin reference names that the user cannot otherwise view in the UI. The endpoint is read-only and does not permit modification of pipeline data. This issue is fixed in version 26.1.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55632Medium· 4.3GoCD is a continuous deliver server
CVE-2026-68919High· 7.0GoCD is a continuous deliver server
CVE-2026-55870Low· 2.3GoCD is a continuous deliver server
CVE-2026-55060Low· 3.7GoCD is a continuous deliver server
CVE-2026-52741High· 7.5GoCD is a continuous deliver server
CVE-2026-52742Medium· 5.1GoCD is a continuous deliver server