{"id":"CVE-2026-55632","summary":"GoCD is vulnerable to authorization bypass via pipeline structure API","details":"GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal pipeline structure API used for autocompletion while editing pipeline, template, environment, and user-preference configuration returns its users-and-roles mode to regular authenticated users without requiring an administrator role. A lower-privileged user can enumerate configured user names and available role names, which can facilitate attacks against those users. The response does not reveal which roles are assigned to each user, and the endpoint cannot modify data. This issue is fixed in version 26.1.0.","aliases":["GHSA-57pf-j652-c3c9"],"modified":"2026-09-25T08:21:38.790255Z","published":"2026-09-23T17:59:10.151Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55632.json"},"references":[{"type":"WEB","url":"https://github.com/gocd/gocd/releases/tag/26.1.0"},{"type":"WEB","url":"https://www.gocd.org/releases/#26-1-0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55632.json"},{"type":"ADVISORY","url":"https://github.com/gocd/gocd/security/advisories/GHSA-57pf-j652-c3c9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55632"},{"type":"FIX","url":"https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gocd/gocd","events":[{"introduced":"0cb6660ad91a19a4064e6537374c896506add24a"},{"fixed":"c93d9e7b32b64257725a7d1c6f148fb571c86c7e"},{"fixed":"55b7b460510bb739c1ae6d226ff7fb650596dca2"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"20.2.0"},{"fixed":"26.1.0"}]}}],"versions":["25.4.0","25.3.0","25.2.0","25.1.0","24.5.0","24.4.0","24.3.0","24.2.0","24.1.0","23.5.0","23.4.0","23.3.0","23.2.0","23.1.0","22.3.0","22.2.0","22.1.0","21.4.0","21.3.0","21.2.0","21.1.0","20.10.0","20.9.0","20.8.0","20.7.0","20.6.0","20.5.0","20.4.0","20.3.0","20.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55632.json","vanir_signatures_modified":"2026-09-25T08:21:38Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["333250038150050460970613601426944663656","197394096272454425432364807494976158718","56694466699412405674866756295020967973","1118424724147717715902643443234785182","334963513759187401697549384968860105522","182858517621921831146759894570091883842","56601789741454755462687060138069816238","289715084555198692103164404971513810478","121176806431652605038673209114271798325","85088448496883991638773104949197806252","12267408249900220415873285355481328379","82793195245657392504497843897713744291","242192300077177380897839660397083469290","7806429424660165352161600540378659043","43561958995458037827562201633845971089","33706971818309980955655573625774120213","202732093696305880071618775412988612901","1817830407142651309060984211898708266","52782994030307084278276183269762614845","250381115111373298315224824095417918890","189621445781802418581706654447805731997","197707958871403456464863241764883708884","26816405952158409974818758263764075279","305682186505147991579535617861314346860","12267408249900220415873285355481328379","67908157636486302219844838982355664516","93672510394505743510902141606593081800","234011853694980244337558757706837536361","143545719526770550214947611383876811059","250485956007253302153348323628292452743","314374039821353392059765529961059686794","150104602141507968626115378905720349531","27056909224871341172647903154631735060","258933367510321204830665377318788102784","133865243158458206548371874878575063907","21269124654314616985275038925347444122","36206925572664844624405799909843668714","106993691230073905671474436338225910116","8048822272164410245792561099239409184","12541967386376870383290631541984183312","216036499173099197753252621158583781683","10390006263810903661002842050848999454","76619443359120195893660387355820176945","226149882439339595961033179824413735994"],"threshold":0.9},"id":"CVE-2026-55632-1ca41eec","signature_type":"Line","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e","target":{"file":"server/src/test/java/com/thoughtworks/go/server/service/SecurityServiceTest.java"}},{"deprecated":false,"digest":{"line_hashes":["293644107583814706305313834881514248581","43526100860380261015420273856821442599","157233936825244187698220557484897351053"],"threshold":0.9},"id":"CVE-2026-55632-1edf0217","signature_type":"Line","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/55b7b460510bb739c1ae6d226ff7fb650596dca2","target":{"file":"server/src/test/java/com/thoughtworks/go/server/service/ConsoleServiceTest.java"}},{"target":{"file":"config/config-api/src/main/java/com/thoughtworks/go/config/TemplatesConfig.java"},"deprecated":false,"digest":{"line_hashes":["249061096466498361826597497257586409418","250855353492564735156234485269364149105","97813689620916711908363018399263922812","96047802447028823066012220500207417434","118096852469081565967996889408233498610","110978307398904818498180124732785825359","102773042227712380051185624212894701760","193945555105656936453847297800470789796","295161427100822763564985225912041757999","153336443156832678084370716145513433271","221236598432928689948922137935164541365","213079481573333358417695039405189181724","267528277723292776719909842070158350320","295367330182491836797181706160915329496","102773042227712380051185624212894701760","193945555105656936453847297800470789796","211611145752054767690561973252997409020","136261687678079187156215213172497340020"],"threshold":0.9},"id":"CVE-2026-55632-2339f081","signature_type":"Line","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e"},{"deprecated":false,"digest":{"function_hash":"250222003766494194465964995240362262739","length":800},"id":"CVE-2026-55632-27d5397f","signature_type":"Function","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/55b7b460510bb739c1ae6d226ff7fb650596dca2","target":{"function":"shouldReturnUsefulErrorIfMoveConsoleArtifactsFails","file":"server/src/test/java/com/thoughtworks/go/server/service/ConsoleServiceTest.java"}},{"target":{"file":"config/config-api/src/main/java/com/thoughtworks/go/config/TemplatesConfig.java","function":"canUserViewTemplates"},"deprecated":false,"digest":{"function_hash":"245233417312508471376456374087677245576","length":194},"id":"CVE-2026-55632-2f2852c5","signature_type":"Function","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e"},{"deprecated":false,"digest":{"line_hashes":["10981243565857719127791900219010226372","207265467836337817429463444169877682428","314021028738877318276781149687110180394","133735678341692987037049683489278036665"],"threshold":0.9},"id":"CVE-2026-55632-371cf8d7","signature_type":"Line","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e","target":{"file":"server/src/main/java/com/thoughtworks/go/server/security/AuthorityGranter.java"}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e","target":{"file":"server/src/test/java/com/thoughtworks/go/server/web/GoCDFreeMarkerViewTest.java","function":"shouldSetTemplateViewUserRightsForTemplateViewUser"},"deprecated":false,"digest":{"function_hash":"193473904887426063809600878803878124431","length":266},"id":"CVE-2026-55632-50d1ed3e"},{"digest":{"line_hashes":["269597057149872946145003914870881517919","169811028015025147391735915040359246151","32050647151862968723723523188540912466","172548583051477418794187658801173093395","224353042861451415711043377238378418286","124104820035561184814576847139040262944","168356199048234105058711403005045156907","42474004110084466192791256303005418367","33243228346922074603272943762753181772","238653346855070451287657159835101906927","206332048293867447884944898701653200754","157328618473810965106974286044924812440","299713909440768687785998023128895574434","188629905178788418864819273227540605221","266491101232994358166698671040371948154","155331083012383678376287621172759182865","116462581481958260799138214631080471925","94634355527461791271688608607944446559","263177561111433509591108177734568543198","19463890642425951716385684630038597044"],"threshold":0.9},"id":"CVE-2026-55632-57f2a806","signature_type":"Line","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e","target":{"file":"server/src/test/java/com/thoughtworks/go/server/web/GoCDFreeMarkerViewTest.java"},"deprecated":false},{"signature_version":"v1","source":"https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e","target":{"file":"api/api-internal-pipeline-structure-v1/src/main/java/com/thoughtworks/go/apiv1/internalpipelinestructure/InternalPipelineStructureControllerV1.java","function":"index"},"deprecated":false,"digest":{"function_hash":"267515683316437307906611071639817707032","length":1154},"id":"CVE-2026-55632-59553c75","signature_type":"Function"},{"signature_version":"v1","source":"https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e","target":{"file":"config/config-api/src/test/java/com/thoughtworks/go/config/TemplatesConfigTest.java"},"deprecated":false,"digest":{"line_hashes":["315482410195003618917222720654787127131","306948776187764705893673645379340243749","207046805182065593317340053756412963134","162939805652626205007147085663462909015","334998498787279924136670003352379531839","189343553983090640559384632669787972525","106873193851961219830356398395438803657","57203324831844455817720942565750977993","235867774222596860339153604206850622711","193645088654720840036028234599857161752","166983085321068758553381340852296900269","173630190781259382180899596988035895186","198615767744691418195312415620866499280","189949134279555362835988714087073433377","9677461538745141187169162789071903988","186553492073103536500268432184307506259","38527250914949164803786671148422137356","329516988778724112815016226184221805718","147630048985674826296002155159530738411","274862369296424245475348425013112008812"],"threshold":0.9},"id":"CVE-2026-55632-5e064738","signature_type":"Line"},{"deprecated":false,"digest":{"line_hashes":["232312850683292018696424080560515488917","42031127979247854171325114100889029244","319684090126633882415731715872017107684","99662251393401887294243092818900026059","141532814493611000742865136948457448064","324180535017301500248453748793472603787","211527399896696030799180558713336860163","169316652420066941652776605674232028940","78764756962908888695939915815165913876","226603401877927722181206409199927661934","265763291128643855848310174428437198369"],"threshold":0.9},"id":"CVE-2026-55632-6a5d7861","signature_type":"Line","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e","target":{"file":"spark/spark-base/src/main/java/com/thoughtworks/go/spark/spring/AbstractAuthorizationHelper.java"}},{"deprecated":false,"digest":{"function_hash":"338610341597706532549911325013042820874","length":110},"id":"CVE-2026-55632-7c6b8a35","signature_type":"Function","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e","target":{"function":"isAuthorizedToViewAndEditTemplates","file":"server/src/main/java/com/thoughtworks/go/server/service/SecurityService.java"}},{"id":"CVE-2026-55632-84f73dfa","signature_type":"Line","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e","target":{"file":"server/src/main/java/com/thoughtworks/go/server/service/PipelineConfigService.java"},"deprecated":false,"digest":{"line_hashes":["137438198966092856611749433170465855415","4235137487809198288097447287280781606","192443576653510705940264877553002586135","97722689768378058736367297566246012296"],"threshold":0.9}},{"deprecated":false,"digest":{"line_hashes":["65631211934572334926327143790708874657","122494591438060977934036579386804202599","294406977139586323154988671290863524859","284094896741509260685374555434683323287"],"threshold":0.9},"id":"CVE-2026-55632-910a6be9","signature_type":"Line","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e","target":{"file":"api/api-internal-pipeline-groups-v1/src/main/java/com/thoughtworks/go/apiv1/internalpipelinegroups/InternalPipelineGroupsControllerV1.java"}},{"deprecated":false,"digest":{"line_hashes":["335337321127870225108490824393513132694","256761516831390480046241453372719958345","219020504509155428612224254217509867283","337813601549947420725995143889287696799","277900629760194121146171555380025134236","288322290144696459012031252105424778992","299756983782240530566768361020821436220","89850685835044213678497079452607303372","171092871074392594429198624041999698586","98323432251838861593982649413630480566","32421747456682447989891365538096412225","248156594317850669428744013099191975845","73984392347355971031343571612911718752","135911103418913560741059265680431815375","187597380869256807600310914863789070250","87208145212883438646117317081299712909","337188198488660977868978877065566211888","1902323432479387270138278604101970108"],"threshold":0.9},"id":"CVE-2026-55632-99740975","signature_type":"Line","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e","target":{"file":"server/src/main/java/com/thoughtworks/go/server/service/SecurityService.java"}},{"deprecated":false,"digest":{"line_hashes":["36443347366154974878393858230838246889","267005500513550798233373799540757953107","186866851626905684216483352742747792069","88989491306508172419154978618399179127","165112586606126967000370333111154388766","65631211934572334926327143790708874657","122494591438060977934036579386804202599","294406977139586323154988671290863524859","186264357308571841659655966224209380961","213197761151759066822500731267059771250","62233844475618613020176381000957395423","83063590349925974848886406035637350044","230215802585085746386294689308586826862","251353720434244563839671137839521541310"],"threshold":0.9},"id":"CVE-2026-55632-bd0f3ec0","signature_type":"Line","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e","target":{"file":"api/api-internal-pipeline-structure-v1/src/main/java/com/thoughtworks/go/apiv1/internalpipelinestructure/InternalPipelineStructureControllerV1.java"}},{"target":{"file":"server/src/test/java/com/thoughtworks/go/server/security/AuthorityGranterTest.java"},"deprecated":false,"digest":{"line_hashes":["196364254230819224899797175377903191885","181431039345021096426776164123719241956","329901441614591780415327098290477190648","201888538819820275445416760747532172963","11144338596293491895865252988700670249","170248604577576448878755106247739251585","33988271489489421755918513038363466193","155614853353916966161492661992792933671"],"threshold":0.9},"id":"CVE-2026-55632-c72135f9","signature_type":"Line","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e","target":{"file":"server/src/main/java/com/thoughtworks/go/server/service/SecurityService.java","function":"canViewAdminPage"},"deprecated":false,"digest":{"function_hash":"218600295357185969186681158878557316610","length":128},"id":"CVE-2026-55632-c8aabbac"},{"id":"CVE-2026-55632-d7761c97","signature_type":"Line","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e","target":{"file":"config/config-api/src/main/java/com/thoughtworks/go/config/BasicCruiseConfig.java"},"deprecated":false,"digest":{"line_hashes":["46348169409027152342248695728686241255","177055656215082034944305736566590775483","186808938279615692036126557682485072037","55825948147073943269746050021983420122","162751301544944082787707866729271761374","87546566986329235310262369360947884664","55831089724284849838497035933685060894","20729608530323448810732182546248174426","116764654757210251861658851953136197190"],"threshold":0.9}},{"id":"CVE-2026-55632-d8e0c27e","signature_type":"Line","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e","target":{"file":"server/src/main/java/com/thoughtworks/go/server/web/GoCDFreeMarkerView.java"},"deprecated":false,"digest":{"line_hashes":["200956054290136525779566449360436949245","209484852464868949304613816342154274274","224112960404858613869847917084469983506","40310452620269998622329966201485109690","266215339215226236760214343042543109976","239504434440815735138851545722402408094","328587530360992513270216944223166975119","39798718009923114840004825023399569243","234690937641939989448442851453155555889","261667999301256003660003893914573806625","137354663013043356215205161851824713354","64531564201315655008824082966430200835","280363983430166195595761681406449016969"],"threshold":0.9}},{"deprecated":false,"digest":{"function_hash":"79808650657460650775111458286246952701","length":273},"id":"CVE-2026-55632-de443d2f","signature_type":"Function","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e","target":{"file":"server/src/test/java/com/thoughtworks/go/server/web/GoCDFreeMarkerViewTest.java","function":"shouldSetViewAdministratorRightsIfUserHasAnyLevelOfAdministratorRights"}},{"target":{"file":"server/src/main/java/com/thoughtworks/go/server/web/GoCDFreeMarkerView.java","function":"exposeHelpers"},"deprecated":false,"digest":{"function_hash":"124775835132795808386200696656339718995","length":1347},"id":"CVE-2026-55632-e2f73e76","signature_type":"Function","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e","target":{"file":"server/src/test-integration/java/com/thoughtworks/go/server/service/SecurityServiceIntegrationTest.java"},"deprecated":false,"digest":{"line_hashes":["67943306061702038381385171923362904255","185300076910138035525822250380314395991","121216448917787019276669753217537791348","120962641294880186719650655878944325031"],"threshold":0.9},"id":"CVE-2026-55632-fbfec995"},{"source":"https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e","target":{"file":"server/src/test/java/com/thoughtworks/go/server/web/GoCDFreeMarkerViewTest.java","function":"shouldSetTemplateAdministratorIfUserIsTemplateAdministrator"},"deprecated":false,"digest":{"function_hash":"131227498527109011713554453413027104082","length":270},"id":"CVE-2026-55632-fd2abe63","signature_type":"Function","signature_version":"v1"},{"target":{"file":"config/config-api/src/main/java/com/thoughtworks/go/config/CruiseConfig.java"},"deprecated":false,"digest":{"line_hashes":["207839838183313144732661939414958286542","197229498716736549257916105433904620162","312659463067354285682406566687714891021","72620360405529830338434471760769750265"],"threshold":0.9},"id":"CVE-2026-55632-fe170d9c","signature_type":"Line","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e"},{"source":"https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e","target":{"file":"config/config-api/src/main/java/com/thoughtworks/go/config/TemplatesConfig.java","function":"canViewAndEditTemplate"},"deprecated":false,"digest":{"function_hash":"306363743807833531450538912189237422975","length":172},"id":"CVE-2026-55632-ffc25744","signature_type":"Function","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}