cve-2026-52744
MEDIUM CVSS 5.3 opencve
Description
GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal GoCD UI fetch-artifact auto-suggestion API at /go/api/internal/pipelines/**/upstream does not adequately authorize access to upstream dependency data. An authenticated user can retrieve inter-pipeline dependency hierarchy details and user-defined pipeline, stage, job, and artifact plugin reference names that the user cannot otherwise view in the UI. The endpoint is read-only and does not permit modification of pipeline data. This issue is fixed in version 26.1.0.
Timeline
- Published
- 2026-09-23 19:17 UTC
- Last Modified
- 2026-09-23
CVSS Details
CVSS details not available.
Affected Products
No product information available.
Weaknesses (CWE)
CVSS metrics
| Version | Base | Severity | Vector | Exploitability | Impact | Source |
|---|---|---|---|---|---|---|
| 4.0 | 5.3 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
mitre | ||
| 4.0 | 5.3 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
nvd | ||
| 4.0 | 5.3 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
opencve |
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cve": "CVE-2026-52744",
"enrichment": {
"affected": [
{
"configurations": [
{
"platform": null,
"status": "affected",
"versions": {
"scheme": "semver",
"value": "[20.2.0,26.1.0)"
}
}
],
"enrichment": {
"confidence": 100.0,
"confidence_source": "matching",
"scores": [
{
"score": 100.0,
"source": "matching"
}
]
},
"original": {
"product": "gocd",
"source": "cna",
"vendor": "gocd"
},
"product": "gocd",
"vendor": "gocd"
}
],
"created": "2026-09-23T20:00:08.602701+00:00",
"updated": "2026-09-23T20:00:08.989005+00:00",
"vendors": [
"gocd",
"gocd$PRODUCT$gocd"
]
},
"mitre": {
"cpes": [],
"created": "2026-09-23T17:58:52.039000+00:00",
"description": "GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal GoCD UI fetch-artifact auto-suggestion API at /go/api/internal/pipelines/**/upstream does not adequately authorize access to upstream dependency data. An authenticated user can retrieve inter-pipeline dependency hierarchy details and user-defined pipeline, stage, job, and artifact plugin reference names that the user cannot otherwise view in the UI. The endpoint is read-only and does not permit modification of pipeline data. This issue is fixed in version 26.1.0.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {},
"cvssV4_0": {
"score": 5.3,
"vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
}
},
"mitre_repo_path": "cves/2026/52xxx/CVE-2026-52744.json",
"references": [
"https://github.com/gocd/gocd/commit/ce9602d7bb27dcb89bf8fc15eb859306cdc8995c",
"https://github.com/gocd/gocd/releases/tag/26.1.0",
"https://github.com/gocd/gocd/security/advisories/GHSA-mvpm-hmc9-2q8p",
"https://www.gocd.org/releases/#26-1-0"
],
"title": "GoCD is vulnerable to authorization bypass via fetch artifact autosuggestion API",
"updated": "2026-09-23T17:58:52.039000+00:00",
"vendors": [],
"weaknesses": [
"CWE-862"
]
},
"nvd": {
"cpes": [],
"created": "2026-09-23T19:17:30.377000+00:00",
"description": "GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal GoCD UI fetch-artifact auto-suggestion API at /go/api/internal/pipelines/**/upstream does not adequately authorize access to upstream dependency data. An authenticated user can retrieve inter-pipeline dependency hierarchy details and user-defined pipeline, stage, job, and artifact plugin reference names that the user cannot otherwise view in the UI. The endpoint is read-only and does not permit modification of pipeline data. This issue is fixed in version 26.1.0.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {},
"cvssV4_0": {
"score": 5.3,
"vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"nvd_repo_path": "2026/CVE-2026-52744.json",
"references": [
"https://github.com/gocd/gocd/commit/ce9602d7bb27dcb89bf8fc15eb859306cdc8995c",
"https://github.com/gocd/gocd/releases/tag/26.1.0",
"https://github.com/gocd/gocd/security/advisories/GHSA-mvpm-hmc9-2q8p",
"https://www.gocd.org/releases/#26-1-0"
],
"title": null,
"updated": "2026-09-23T19:17:30.377000+00:00",
"vendors": [],
"weaknesses": [
"CWE-862"
]
},
"opencve": {
"changes": [
{
"created": "2026-09-23T18:30:00+00:00",
"data": [
{
"details": {
"new": "GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal GoCD UI fetch-artifact auto-suggestion API at /go/api/internal/pipelines/**/upstream does not adequately authorize access to upstream dependency data. An authenticated user can retrieve inter-pipeline dependency hierarchy details and user-defined pipeline, stage, job, and artifact plugin reference names that the user cannot otherwise view in the UI. The endpoint is read-only and does not permit modification of pipeline data. This issue is fixed in version 26.1.0.",
"old": null
},
"type": "description"
},
{
"details": {
"new": "GoCD is vulnerable to authorization bypass via fetch artifact autosuggestion API",
"old": null
},
"type": "title"
},
{
"details": {
"added": [
"CWE-862"
],
"removed": []
},
"type": "weaknesses"
},
{
"details": {
"added": [
"https://github.com/gocd/gocd/commit/ce9602d7bb27dcb89bf8fc15eb859306cdc8995c",
"https://github.com/gocd/gocd/releases/tag/26.1.0",
"https://github.com/gocd/gocd/security/advisories/GHSA-mvpm-hmc9-2q8p",
"https://www.gocd.org/releases/#26-1-0"
],
"removed": []
},
"type": "references"
},
{
"details": {
"added": {
"cvssV4_0": {
"score": 5.3,
"vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "2b0ccfe6-3071-40cc-9f1c-6995560c1240"
},
{
"created": "2026-09-23T20:15:00+00:00",
"data": [
{
"details": [
"gocd",
"gocd$PRODUCT$gocd"
],
"type": "first_time"
},
{
"details": {
"added": [
"gocd",
"gocd$PRODUCT$gocd"
],
"removed": []
},
"type": "vendors"
}
],
"id": "7ed93b66-a859-432f-a366-bf39ccbb0c02"
}
],
"cpes": {
"data": [],
"providers": []
},
"created": {
"data": "2026-09-23T17:58:52.039000+00:00",
"provider": "mitre"
},
"description": {
"data": "GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal GoCD UI fetch-artifact auto-suggestion API at /go/api/internal/pipelines/**/upstream does not adequately authorize access to upstream dependency data. An authenticated user can retrieve inter-pipeline dependency hierarchy details and user-defined pipeline, stage, job, and artifact plugin reference names that the user cannot otherwise view in the UI. The endpoint is read-only and does not permit modification of pipeline data. This issue is fixed in version 26.1.0.",
"provider": "mitre"
},
"metrics": {
"cvssV2_0": {
"data": {},
"provider": null
},
"cvssV3_0": {
"data": {},
"provider": null
},
"cvssV3_1": {
"data": {},
"provider": null
},
"cvssV4_0": {
"data": {
"score": 5.3,
"vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
},
"provider": "mitre"
},
"epss": {
"data": {},
"provider": null
},
"kev": {
"data": {},
"provider": null
},
"ssvc": {
"data": {},
"provider": null
},
"threat_severity": {
"data": null,
"provider": null
}
},
"references": {
"data": [
"https://github.com/gocd/gocd/commit/ce9602d7bb27dcb89bf8fc15eb859306cdc8995c",
"https://github.com/gocd/gocd/releases/tag/26.1.0",
"https://github.com/gocd/gocd/security/advisories/GHSA-mvpm-hmc9-2q8p",
"https://www.gocd.org/releases/#26-1-0"
],
"providers": [
"mitre",
"nvd"
]
},
"title": {
"data": "GoCD is vulnerable to authorization bypass via fetch artifact autosuggestion API",
"provider": "mitre"
},
"updated": {
"data": "2026-09-23T20:00:08.989005+00:00",
"provider": "enrichment"
},
"vendors": {
"data": [
"gocd",
"gocd$PRODUCT$gocd"
],
"providers": [
"enrichment"
]
},
"weaknesses": {
"data": [
"CWE-862"
],
"providers": [
"mitre",
"nvd"
]
}
}
}