← Back to search

CVE-2026-55060

3.7 LOWpublic exploit available

Published 2026-09-21 · Updated 2026-09-21

AI risk analysis

Summary
The flaw allows an authenticated internal user to view sensitive information from source control child processes, including command-line arguments and material paths, which could be exploited for unauthorized access.
Exploitability
Exploitation is moderately difficult due to timing dependencies but requires the attacker to have valid credentials and knowledge of running processes.
Blast radius
If exploited, the impact is limited to viewing masked or omitted sensitive information, potentially leading to data exposure or misconfiguration issues.
Prioritized remediation
Upgrade to GoCD version 26.1.0 immediately to address the authorization vulnerability.
auth-bypassinfo-leakweb

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

GoCD is a continuous deliver server. From 13.1.0 until 26.1.0, the /go/api/support/process_list endpoint does not enforce its intended administrator-only authorization. An authenticated internal user can query the endpoint while source control child processes are running and view command-line arguments, usernames, remote material URLs, and internal material paths for materials the user cannot otherwise access. Exploitation depends on unpredictable process timing, and credentials, environment variables, and user-defined secrets remain masked or omitted. This issue is fixed in version 26.1.0.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Weaknesses

CWE-863

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.