VYPR
Medium severityNVD Advisory· Published Sep 23, 2026

CVE-2026-52744

CVE-2026-52744

Description

GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal GoCD UI fetch-artifact auto-suggestion API at /go/api/internal/pipelines/**/upstream does not adequately authorize access to upstream dependency data. An authenticated user can retrieve inter-pipeline dependency hierarchy details and user-defined pipeline, stage, job, and artifact plugin reference names that the user cannot otherwise view in the UI. The endpoint is read-only and does not permit modification of pipeline data. This issue is fixed in version 26.1.0.

Affected products

1
  • GoCD/Gocdllm-fuzzy
    Range: 20.2.0 - 26.1.0

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.