Security Issue in GoCD Continuous Delivery Server Affecting Configuration Privacy
CVE-2026-52742
5.1MEDIUM
What is CVE-2026-52742?
In GoCD, a continuous delivery server, a security vulnerability exists in versions ranging from 12.3.1 to 26.0.0 where legacy routes under /go/admin/restful/* inadvertently expose sensitive historical server configurations to pipeline group administrators. This allows these administrators to access configuration data for groups they do not manage, leading to the potential compromise of critical components like agent auto-registration keys and encrypted credentials. A malicious user with administrator rights could leverage this information to add rogue agents that could manipulate deployments or overwrite artifacts. This issue has been addressed and resolved in version 26.1.0.
Affected Version(s)
gocd >= 12.3.1, < 26.1.0
