GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal pipeline structure API used for autocompletion while editing pipeline, template, environment, and user-preference configuration returns its users-and-roles mode to regular authenticated users without requiring an administrator role. A lower-privileged user can enumerate configured user names and available role names, which can facilitate attacks against those users. The response does not reveal which roles are assigned to each user, and the endpoint cannot modify data. This issue is fixed in version 26.1.0.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-863"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55632.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55632.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"333250038150050460970613601426944663656",
"197394096272454425432364807494976158718",
"56694466699412405674866756295020967973",
"1118424724147717715902643443234785182",
"334963513759187401697549384968860105522",
"182858517621921831146759894570091883842",
"56601789741454755462687060138069816238",
"289715084555198692103164404971513810478",
"121176806431652605038673209114271798325",
"85088448496883991638773104949197806252",
"12267408249900220415873285355481328379",
"82793195245657392504497843897713744291",
"242192300077177380897839660397083469290",
"7806429424660165352161600540378659043",
"43561958995458037827562201633845971089",
"33706971818309980955655573625774120213",
"202732093696305880071618775412988612901",
"1817830407142651309060984211898708266",
"52782994030307084278276183269762614845",
"250381115111373298315224824095417918890",
"189621445781802418581706654447805731997",
"197707958871403456464863241764883708884",
"26816405952158409974818758263764075279",
"305682186505147991579535617861314346860",
"12267408249900220415873285355481328379",
"67908157636486302219844838982355664516",
"93672510394505743510902141606593081800",
"234011853694980244337558757706837536361",
"143545719526770550214947611383876811059",
"250485956007253302153348323628292452743",
"314374039821353392059765529961059686794",
"150104602141507968626115378905720349531",
"27056909224871341172647903154631735060",
"258933367510321204830665377318788102784",
"133865243158458206548371874878575063907",
"21269124654314616985275038925347444122",
"36206925572664844624405799909843668714",
"106993691230073905671474436338225910116",
"8048822272164410245792561099239409184",
"12541967386376870383290631541984183312",
"216036499173099197753252621158583781683",
"10390006263810903661002842050848999454",
"76619443359120195893660387355820176945",
"226149882439339595961033179824413735994"
],
"threshold": 0.9
},
"id": "CVE-2026-55632-1ca41eec",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e",
"target": {
"file": "server/src/test/java/com/thoughtworks/go/server/service/SecurityServiceTest.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"293644107583814706305313834881514248581",
"43526100860380261015420273856821442599",
"157233936825244187698220557484897351053"
],
"threshold": 0.9
},
"id": "CVE-2026-55632-1edf0217",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gocd/gocd/commit/55b7b460510bb739c1ae6d226ff7fb650596dca2",
"target": {
"file": "server/src/test/java/com/thoughtworks/go/server/service/ConsoleServiceTest.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"249061096466498361826597497257586409418",
"250855353492564735156234485269364149105",
"97813689620916711908363018399263922812",
"96047802447028823066012220500207417434",
"118096852469081565967996889408233498610",
"110978307398904818498180124732785825359",
"102773042227712380051185624212894701760",
"193945555105656936453847297800470789796",
"295161427100822763564985225912041757999",
"153336443156832678084370716145513433271",
"221236598432928689948922137935164541365",
"213079481573333358417695039405189181724",
"267528277723292776719909842070158350320",
"295367330182491836797181706160915329496",
"102773042227712380051185624212894701760",
"193945555105656936453847297800470789796",
"211611145752054767690561973252997409020",
"136261687678079187156215213172497340020"
],
"threshold": 0.9
},
"id": "CVE-2026-55632-2339f081",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e",
"target": {
"file": "config/config-api/src/main/java/com/thoughtworks/go/config/TemplatesConfig.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "250222003766494194465964995240362262739",
"length": 800
},
"id": "CVE-2026-55632-27d5397f",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gocd/gocd/commit/55b7b460510bb739c1ae6d226ff7fb650596dca2",
"target": {
"file": "server/src/test/java/com/thoughtworks/go/server/service/ConsoleServiceTest.java",
"function": "shouldReturnUsefulErrorIfMoveConsoleArtifactsFails"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "245233417312508471376456374087677245576",
"length": 194
},
"id": "CVE-2026-55632-2f2852c5",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e",
"target": {
"file": "config/config-api/src/main/java/com/thoughtworks/go/config/TemplatesConfig.java",
"function": "canUserViewTemplates"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"10981243565857719127791900219010226372",
"207265467836337817429463444169877682428",
"314021028738877318276781149687110180394",
"133735678341692987037049683489278036665"
],
"threshold": 0.9
},
"id": "CVE-2026-55632-371cf8d7",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e",
"target": {
"file": "server/src/main/java/com/thoughtworks/go/server/security/AuthorityGranter.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "193473904887426063809600878803878124431",
"length": 266
},
"id": "CVE-2026-55632-50d1ed3e",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e",
"target": {
"file": "server/src/test/java/com/thoughtworks/go/server/web/GoCDFreeMarkerViewTest.java",
"function": "shouldSetTemplateViewUserRightsForTemplateViewUser"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"269597057149872946145003914870881517919",
"169811028015025147391735915040359246151",
"32050647151862968723723523188540912466",
"172548583051477418794187658801173093395",
"224353042861451415711043377238378418286",
"124104820035561184814576847139040262944",
"168356199048234105058711403005045156907",
"42474004110084466192791256303005418367",
"33243228346922074603272943762753181772",
"238653346855070451287657159835101906927",
"206332048293867447884944898701653200754",
"157328618473810965106974286044924812440",
"299713909440768687785998023128895574434",
"188629905178788418864819273227540605221",
"266491101232994358166698671040371948154",
"155331083012383678376287621172759182865",
"116462581481958260799138214631080471925",
"94634355527461791271688608607944446559",
"263177561111433509591108177734568543198",
"19463890642425951716385684630038597044"
],
"threshold": 0.9
},
"id": "CVE-2026-55632-57f2a806",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e",
"target": {
"file": "server/src/test/java/com/thoughtworks/go/server/web/GoCDFreeMarkerViewTest.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "267515683316437307906611071639817707032",
"length": 1154
},
"id": "CVE-2026-55632-59553c75",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e",
"target": {
"file": "api/api-internal-pipeline-structure-v1/src/main/java/com/thoughtworks/go/apiv1/internalpipelinestructure/InternalPipelineStructureControllerV1.java",
"function": "index"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"315482410195003618917222720654787127131",
"306948776187764705893673645379340243749",
"207046805182065593317340053756412963134",
"162939805652626205007147085663462909015",
"334998498787279924136670003352379531839",
"189343553983090640559384632669787972525",
"106873193851961219830356398395438803657",
"57203324831844455817720942565750977993",
"235867774222596860339153604206850622711",
"193645088654720840036028234599857161752",
"166983085321068758553381340852296900269",
"173630190781259382180899596988035895186",
"198615767744691418195312415620866499280",
"189949134279555362835988714087073433377",
"9677461538745141187169162789071903988",
"186553492073103536500268432184307506259",
"38527250914949164803786671148422137356",
"329516988778724112815016226184221805718",
"147630048985674826296002155159530738411",
"274862369296424245475348425013112008812"
],
"threshold": 0.9
},
"id": "CVE-2026-55632-5e064738",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e",
"target": {
"file": "config/config-api/src/test/java/com/thoughtworks/go/config/TemplatesConfigTest.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"232312850683292018696424080560515488917",
"42031127979247854171325114100889029244",
"319684090126633882415731715872017107684",
"99662251393401887294243092818900026059",
"141532814493611000742865136948457448064",
"324180535017301500248453748793472603787",
"211527399896696030799180558713336860163",
"169316652420066941652776605674232028940",
"78764756962908888695939915815165913876",
"226603401877927722181206409199927661934",
"265763291128643855848310174428437198369"
],
"threshold": 0.9
},
"id": "CVE-2026-55632-6a5d7861",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e",
"target": {
"file": "spark/spark-base/src/main/java/com/thoughtworks/go/spark/spring/AbstractAuthorizationHelper.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "338610341597706532549911325013042820874",
"length": 110
},
"id": "CVE-2026-55632-7c6b8a35",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e",
"target": {
"file": "server/src/main/java/com/thoughtworks/go/server/service/SecurityService.java",
"function": "isAuthorizedToViewAndEditTemplates"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"137438198966092856611749433170465855415",
"4235137487809198288097447287280781606",
"192443576653510705940264877553002586135",
"97722689768378058736367297566246012296"
],
"threshold": 0.9
},
"id": "CVE-2026-55632-84f73dfa",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e",
"target": {
"file": "server/src/main/java/com/thoughtworks/go/server/service/PipelineConfigService.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"65631211934572334926327143790708874657",
"122494591438060977934036579386804202599",
"294406977139586323154988671290863524859",
"284094896741509260685374555434683323287"
],
"threshold": 0.9
},
"id": "CVE-2026-55632-910a6be9",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e",
"target": {
"file": "api/api-internal-pipeline-groups-v1/src/main/java/com/thoughtworks/go/apiv1/internalpipelinegroups/InternalPipelineGroupsControllerV1.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"335337321127870225108490824393513132694",
"256761516831390480046241453372719958345",
"219020504509155428612224254217509867283",
"337813601549947420725995143889287696799",
"277900629760194121146171555380025134236",
"288322290144696459012031252105424778992",
"299756983782240530566768361020821436220",
"89850685835044213678497079452607303372",
"171092871074392594429198624041999698586",
"98323432251838861593982649413630480566",
"32421747456682447989891365538096412225",
"248156594317850669428744013099191975845",
"73984392347355971031343571612911718752",
"135911103418913560741059265680431815375",
"187597380869256807600310914863789070250",
"87208145212883438646117317081299712909",
"337188198488660977868978877065566211888",
"1902323432479387270138278604101970108"
],
"threshold": 0.9
},
"id": "CVE-2026-55632-99740975",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e",
"target": {
"file": "server/src/main/java/com/thoughtworks/go/server/service/SecurityService.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"36443347366154974878393858230838246889",
"267005500513550798233373799540757953107",
"186866851626905684216483352742747792069",
"88989491306508172419154978618399179127",
"165112586606126967000370333111154388766",
"65631211934572334926327143790708874657",
"122494591438060977934036579386804202599",
"294406977139586323154988671290863524859",
"186264357308571841659655966224209380961",
"213197761151759066822500731267059771250",
"62233844475618613020176381000957395423",
"83063590349925974848886406035637350044",
"230215802585085746386294689308586826862",
"251353720434244563839671137839521541310"
],
"threshold": 0.9
},
"id": "CVE-2026-55632-bd0f3ec0",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e",
"target": {
"file": "api/api-internal-pipeline-structure-v1/src/main/java/com/thoughtworks/go/apiv1/internalpipelinestructure/InternalPipelineStructureControllerV1.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"196364254230819224899797175377903191885",
"181431039345021096426776164123719241956",
"329901441614591780415327098290477190648",
"201888538819820275445416760747532172963",
"11144338596293491895865252988700670249",
"170248604577576448878755106247739251585",
"33988271489489421755918513038363466193",
"155614853353916966161492661992792933671"
],
"threshold": 0.9
},
"id": "CVE-2026-55632-c72135f9",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e",
"target": {
"file": "server/src/test/java/com/thoughtworks/go/server/security/AuthorityGranterTest.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "218600295357185969186681158878557316610",
"length": 128
},
"id": "CVE-2026-55632-c8aabbac",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e",
"target": {
"file": "server/src/main/java/com/thoughtworks/go/server/service/SecurityService.java",
"function": "canViewAdminPage"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"46348169409027152342248695728686241255",
"177055656215082034944305736566590775483",
"186808938279615692036126557682485072037",
"55825948147073943269746050021983420122",
"162751301544944082787707866729271761374",
"87546566986329235310262369360947884664",
"55831089724284849838497035933685060894",
"20729608530323448810732182546248174426",
"116764654757210251861658851953136197190"
],
"threshold": 0.9
},
"id": "CVE-2026-55632-d7761c97",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e",
"target": {
"file": "config/config-api/src/main/java/com/thoughtworks/go/config/BasicCruiseConfig.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"200956054290136525779566449360436949245",
"209484852464868949304613816342154274274",
"224112960404858613869847917084469983506",
"40310452620269998622329966201485109690",
"266215339215226236760214343042543109976",
"239504434440815735138851545722402408094",
"328587530360992513270216944223166975119",
"39798718009923114840004825023399569243",
"234690937641939989448442851453155555889",
"261667999301256003660003893914573806625",
"137354663013043356215205161851824713354",
"64531564201315655008824082966430200835",
"280363983430166195595761681406449016969"
],
"threshold": 0.9
},
"id": "CVE-2026-55632-d8e0c27e",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e",
"target": {
"file": "server/src/main/java/com/thoughtworks/go/server/web/GoCDFreeMarkerView.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "79808650657460650775111458286246952701",
"length": 273
},
"id": "CVE-2026-55632-de443d2f",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e",
"target": {
"file": "server/src/test/java/com/thoughtworks/go/server/web/GoCDFreeMarkerViewTest.java",
"function": "shouldSetViewAdministratorRightsIfUserHasAnyLevelOfAdministratorRights"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "124775835132795808386200696656339718995",
"length": 1347
},
"id": "CVE-2026-55632-e2f73e76",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e",
"target": {
"file": "server/src/main/java/com/thoughtworks/go/server/web/GoCDFreeMarkerView.java",
"function": "exposeHelpers"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"67943306061702038381385171923362904255",
"185300076910138035525822250380314395991",
"121216448917787019276669753217537791348",
"120962641294880186719650655878944325031"
],
"threshold": 0.9
},
"id": "CVE-2026-55632-fbfec995",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e",
"target": {
"file": "server/src/test-integration/java/com/thoughtworks/go/server/service/SecurityServiceIntegrationTest.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "131227498527109011713554453413027104082",
"length": 270
},
"id": "CVE-2026-55632-fd2abe63",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e",
"target": {
"file": "server/src/test/java/com/thoughtworks/go/server/web/GoCDFreeMarkerViewTest.java",
"function": "shouldSetTemplateAdministratorIfUserIsTemplateAdministrator"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"207839838183313144732661939414958286542",
"197229498716736549257916105433904620162",
"312659463067354285682406566687714891021",
"72620360405529830338434471760769750265"
],
"threshold": 0.9
},
"id": "CVE-2026-55632-fe170d9c",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e",
"target": {
"file": "config/config-api/src/main/java/com/thoughtworks/go/config/CruiseConfig.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "306363743807833531450538912189237422975",
"length": 172
},
"id": "CVE-2026-55632-ffc25744",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gocd/gocd/commit/c93d9e7b32b64257725a7d1c6f148fb571c86c7e",
"target": {
"file": "config/config-api/src/main/java/com/thoughtworks/go/config/TemplatesConfig.java",
"function": "canViewAndEditTemplate"
}
}
]
"2026-09-25T08:21:38Z"