Information Disclosure in GoCD Continuous Delivery Server
CVE-2026-52743

4.3MEDIUM

Key Information:

Vendor

Gocd

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-52743?

The GoCD continuous delivery server prior to version 26.1.0 contains a vulnerability where the internal UI and /jobStatus.json API improperly validate job IDs. This flaw allows an authenticated user to guess job IDs and access information regarding jobs in pipelines they are not authorized to view. This access includes insights on job names, their current state, progress timestamps, assigned agent IP addresses, UUIDs, and details about associated stages and pipelines, while excluding sensitive data like console output and artifacts. The issue has been remedied in version 26.1.0.

Affected Version(s)

gocd < 26.1.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.