Medium severityNVD Advisory· Published Sep 23, 2026
CVE-2026-52744
CVE-2026-52744
Description
GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal GoCD UI fetch-artifact auto-suggestion API at /go/api/internal/pipelines/**/upstream does not adequately authorize access to upstream dependency data. An authenticated user can retrieve inter-pipeline dependency hierarchy details and user-defined pipeline, stage, job, and artifact plugin reference names that the user cannot otherwise view in the UI. The endpoint is read-only and does not permit modification of pipeline data. This issue is fixed in version 26.1.0.
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.