Description
GoCD is a continuous deliver server. From 12.3.1 until 26.1.0, legacy routes under /go/admin/restful/* expose historical full server configuration to pipeline group administrators instead of restricting responses to configuration for groups they administer. The disclosed configuration can include agent auto-registration keys, webhook invocation keys, encrypted material credentials, and GoCD administrator lists. A malicious pipeline group administrator can use disclosed agent registration data to connect a rogue compatible agent, which can create a higher-complexity path to receiving work or overwriting artifacts associated with other groups. Normal authenticated users are not affected, the endpoint does not modify server configuration, and deployments that restrict pipeline editing to full administrators or configuration repositories are not affected. This issue is fixed in version 26.1.0.
Published: 2026-09-21
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Authorization bypass exposing historical server configuration, enabling rogue agent registration and potential conflict with other pipeline groups
Action: Patch
AI Analysis

Impact

Legacy RESTful routes under /go/admin/restful/* allowed pipeline group administrators to retrieve the full historical server configuration instead of a filtered view. The exposed data could contain agent auto‑registration keys, webhook invocation keys, encrypted material credentials, and administrator lists. A malicious pipeline group administrator could use the disclosed registration data to add a rogue agent that might obtain work or overwrite artifacts from other groups. The vulnerability does not modify configuration, and ordinary authenticated users cannot exploit it.

Affected Systems

GoCD versions from 12.3.1 through 26.1.0 are affected. The issue is fixed in version 26.1.0 and later releases.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate severity. EPSS is not available, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in CISA KEV. The attack requires an authenticated pipeline group administrator with access to the legacy admin REST API; the attacker then bypasses authorization controls to make full configuration visible.

Generated by OpenCVE AI on September 21, 2026 at 16:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to GoCD 26.1.0 or later to receive the vendor’s fix
  • If upgrading immediately is not possible, disable or remove the legacy /go/admin/restful/* routes from the server to prevent unauthorized access
  • Re‑issue any auto‑registration keys that may have been exposed by the historical data; revoke and rotate keys for all agents
  • Restrict pipeline editing rights to full administrators or enable configuration repositories to limit the impact of potential misuse

Generated by OpenCVE AI on September 21, 2026 at 16:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Description GoCD is a continuous deliver server. From 12.3.1 until 26.1.0, legacy routes under /go/admin/restful/* expose historical full server configuration to pipeline group administrators instead of restricting responses to configuration for groups they administer. The disclosed configuration can include agent auto-registration keys, webhook invocation keys, encrypted material credentials, and GoCD administrator lists. A malicious pipeline group administrator can use disclosed agent registration data to connect a rogue compatible agent, which can create a higher-complexity path to receiving work or overwriting artifacts associated with other groups. Normal authenticated users are not affected, the endpoint does not modify server configuration, and deployments that restrict pipeline editing to full administrators or configuration repositories are not affected. This issue is fixed in version 26.1.0.
Title GoCD is vulnerable to historical server configuration API authorization bypass
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T15:34:48.735Z

Reserved: 2026-06-08T14:00:43.573Z

Link: CVE-2026-52742

cve-icon Vulnrichment

Updated: 2026-09-21T15:34:42.916Z

cve-icon NVD

Status : Received

Published: 2026-09-21T15:17:28.790

Modified: 2026-09-21T16:17:08.887

Link: CVE-2026-52742

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T16:30:11Z

Weaknesses