GoCD is vulnerable to authorization bypass via pipeline structure API (CVE-2026-55632) | HOL Guard CVE