{"id":"CVE-2026-55060","summary":"GoCD is vulnerable to authorization bypass via support process list API","details":"GoCD is a continuous deliver server. From 13.1.0 until 26.1.0, the /go/api/support/process_list endpoint does not enforce its intended administrator-only authorization. An authenticated internal user can query the endpoint while source control child processes are running and view command-line arguments, usernames, remote material URLs, and internal material paths for materials the user cannot otherwise access. Exploitation depends on unpredictable process timing, and credentials, environment variables, and user-defined secrets remain masked or omitted. This issue is fixed in version 26.1.0.","aliases":["GHSA-vqjf-7pf8-hgwr"],"modified":"2026-09-23T03:47:12.905937534Z","published":"2026-09-21T14:58:39.059Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55060.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-863"]},"references":[{"type":"WEB","url":"https://github.com/gocd/gocd/releases/tag/26.1.0"},{"type":"WEB","url":"https://www.gocd.org/releases/#26-1-0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55060.json"},{"type":"ADVISORY","url":"https://github.com/gocd/gocd/security/advisories/GHSA-vqjf-7pf8-hgwr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55060"},{"type":"FIX","url":"https://github.com/gocd/gocd/commit/fbf832f9358d96466bb87fad11a1de0ba935fea8"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gocd/gocd","events":[{"introduced":"0"},{"fixed":"fbf832f9358d96466bb87fad11a1de0ba935fea8"},{"fixed":"55b7b460510bb739c1ae6d226ff7fb650596dca2"}],"database_specific":{"extracted_events":[{"introduced":"13.1.0"},{"fixed":"26.1.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["25.4.0","25.3.0","25.2.0","25.1.0","24.5.0","24.4.0","24.3.0","24.2.0","24.1.0","23.5.0","23.4.0","23.3.0","23.2.0","23.1.0","22.3.0","22.2.0","22.1.0","21.4.0","21.3.0","21.2.0","21.1.0","20.10.0","20.9.0","20.8.0","20.7.0","20.6.0","20.5.0","20.4.0","20.3.0","20.2.0","20.1.0","19.12.0","19.11.0","19.10.0","19.9.0","19.8.0","19.7.0","19.6.0","19.5.0","19.4.0","19.3.0","19.2.0","19.1.0","18.12.0","18.11.0","18.10.0","18.9.0","18.8.0","18.7.0","18.6.0","18.5.0","18.4.0","18.3.0","18.2.0","18.1.0","17.12.0","17.11.0","17.10.0","17.9.0","17.8.0","17.7.0","17.6.0","17.5.0","17.4.0","17.3.0","17.2.0","17.1.0","16.12.0","16.11.0","16.10.0","16.9.0","16.8.0","16.7.0","16.6.0","16.5.0","16.4.0","16.3.0","16.2.0","16.1.0","15.3.0","15.2.0","15.1.0","14.4.0","14.3.0","14.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55060.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}