Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 21 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 21 Sep 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gocd
Gocd gocd |
|
| Vendors & Products |
Gocd
Gocd gocd |
Mon, 21 Sep 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GoCD is a continuous deliver server. From 13.1.0 until 26.1.0, the /go/api/support/process_list endpoint does not enforce its intended administrator-only authorization. An authenticated internal user can query the endpoint while source control child processes are running and view command-line arguments, usernames, remote material URLs, and internal material paths for materials the user cannot otherwise access. Exploitation depends on unpredictable process timing, and credentials, environment variables, and user-defined secrets remain masked or omitted. This issue is fixed in version 26.1.0. | |
| Title | GoCD is vulnerable to authorization bypass via support process list API | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-21T20:46:04.670Z
Reserved: 2026-06-16T14:33:35.709Z
Link: CVE-2026-55060
Updated: 2026-09-21T19:40:27.289Z
Status : Received
Published: 2026-09-21T15:17:29.277
Modified: 2026-09-21T21:17:05.213
Link: CVE-2026-55060
No data.
OpenCVE Enrichment
Updated: 2026-09-21T19:23:24Z