{"id":"CVE-2026-52744","published":"2026-09-23T19:17:30.377","lastModified":"2026-09-29T02:16:55.360","description":"GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal GoCD UI fetch-artifact auto-suggestion API at /go/api/internal/pipelines/**/upstream does not adequately authorize access to upstream dependency data. An authenticated user can retrieve inter-pipeline dependency hierarchy details and user-defined pipeline, stage, job, and artifact plugin reference names that the user cannot otherwise view in the UI. The endpoint is read-only and does not permit modification of pipeline data. This issue is fixed in version 26.1.0.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-862"],"vendors":[],"products":[],"references":[{"url":"https://github.com/gocd/gocd/commit/ce9602d7bb27dcb89bf8fc15eb859306cdc8995c","tags":[]},{"url":"https://github.com/gocd/gocd/releases/tag/26.1.0","tags":[]},{"url":"https://github.com/gocd/gocd/security/advisories/GHSA-mvpm-hmc9-2q8p","tags":[]},{"url":"https://www.gocd.org/releases/#26-1-0","tags":[]}],"exploitRefs":[{"url":"https://github.com/gocd/gocd/commit/ce9602d7bb27dcb89bf8fc15eb859306cdc8995c","tags":[]},{"url":"https://github.com/gocd/gocd/releases/tag/26.1.0","tags":[]},{"url":"https://github.com/gocd/gocd/security/advisories/GHSA-mvpm-hmc9-2q8p","tags":[]}],"hasPoc":true,"ai":null}