Credential Leak in Gradient Continuous Integration System by Wavelens
CVE-2026-44592
9.4CRITICAL
What is CVE-2026-44592?
The Gradient continuous integration system, particularly version 1.1.0, contains a security flaw that allows users to register as workers without authentication when the GRADIENT_DISCOVERABLE setting is enabled (the default setting). This vulnerability permits unauthorized individuals to access sensitive job data across organizations and execute arbitrary uploads into the nar_storage and cached_path tables. The issue has been remedied in version 1.1.1, which is essential for securing the integration environment.
Affected Version(s)
gradient 1.1.0
