CVE-2026-55060
3.7 LOWpublic exploit availablePublished 2026-09-21 · Updated 2026-09-21
AI risk analysis
- Summary
- The flaw allows an authenticated internal user to view sensitive information from source control child processes, including command-line arguments and material paths, which could be exploited for unauthorized access.
- Exploitability
- Exploitation is moderately difficult due to timing dependencies but requires the attacker to have valid credentials and knowledge of running processes.
- Blast radius
- If exploited, the impact is limited to viewing masked or omitted sensitive information, potentially leading to data exposure or misconfiguration issues.
- Prioritized remediation
- Upgrade to GoCD version 26.1.0 immediately to address the authorization vulnerability.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
GoCD is a continuous deliver server. From 13.1.0 until 26.1.0, the /go/api/support/process_list endpoint does not enforce its intended administrator-only authorization. An authenticated internal user can query the endpoint while source control child processes are running and view command-line arguments, usernames, remote material URLs, and internal material paths for materials the user cannot otherwise access. Exploitation depends on unpredictable process timing, and credentials, environment variables, and user-defined secrets remain masked or omitted. This issue is fixed in version 26.1.0.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Weaknesses
CWE-863
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-52743PoC
- MEDIUMCVE-2025-71420PoC
- HIGHCVE-2026-6639
- MEDIUMCVE-2026-70491PoC
- MEDIUMCVE-2026-75158PoC
- MEDIUMCVE-2026-94213
- MEDIUMCVE-2026-94532PoC
- MEDIUMCVE-2026-55625PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.