{"id":"CVE-2026-52743","published":"2026-09-21T15:17:28.950","lastModified":"2026-09-21T15:17:28.950","description":"GoCD is a continuous deliver server. Prior to 26.1.0, the internal GoCD UI /jobStatus.json API does not validate that a requested server-assigned job ID belongs to the pipeline and stage named in the request. An authenticated user can guess job IDs and retrieve status for jobs in pipelines the user cannot otherwise view, including job names, state, progress timestamps, assigned agent IP addresses and UUIDs, and associated stages and pipelines. The response does not expose console output, artifacts, commands, variables, or configuration. This issue is fixed in version 26.1.0.","cvssScore":4.3,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwes":["CWE-639","CWE-863"],"vendors":[],"products":[],"references":[{"url":"https://github.com/gocd/gocd/commit/07f9ffd16263e0f626c4b7c0fced1b1b854aab1a","tags":[]},{"url":"https://github.com/gocd/gocd/releases/tag/26.1.0","tags":[]},{"url":"https://github.com/gocd/gocd/security/advisories/GHSA-2x6r-h7h3-wqc4","tags":[]},{"url":"https://www.gocd.org/releases/#26-1-0","tags":[]}],"exploitRefs":[{"url":"https://github.com/gocd/gocd/commit/07f9ffd16263e0f626c4b7c0fced1b1b854aab1a","tags":[]},{"url":"https://github.com/gocd/gocd/releases/tag/26.1.0","tags":[]},{"url":"https://github.com/gocd/gocd/security/advisories/GHSA-2x6r-h7h3-wqc4","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows authenticated users to guess job IDs and retrieve status for jobs in pipelines they shouldn't have access to, potentially exposing sensitive information.","exploitability":"Exploitation requires authentication and knowledge of job IDs; guessing is feasible but may require some trial and error.","blast_radius":"If exploited, the impact is limited to exposure of job names, state, progress timestamps, assigned agent details, and associated stages and pipelines.","remediation":"Upgrade to GoCD version 26.1.0 or later to mitigate this vulnerability.","tags":["auth-bypass","info-leak","web"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:32:26.021Z"}}