CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-56782

Critical · CVSS 9.8

Gorse — Authentication Bypass (CWE-306) — Missing Authentication for Critical Function on /api/dump and /api/restore endpoints

CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-306

Description

Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints that allows unauthenticated attackers to access protected functionality when admin_api_key is empty, which is the default configuration. Remote attackers can exfiltrate the entire database including user records, items, and feedback data containing personally identifiable information, or completely overwrite the dataset without authentication.

Search profile — drives PoC discovery

Symbols /api/dump/api/restoreadmin_api_keyAdminAPIKeygorsedumprestore19fdcbb309fb5b609e9cc3eb10c74885b5b27da9
Keywords CVE-2026-56782Gorse authentication bypassGorse api/dump unauthenticatedGorse api/restore unauthenticatedGorse admin_api_key emptyGorse database dump exploitGorse 0.5.10gorse-io authentication bypass PoCCWE-306 GorseGorse unauthenticated database exfiltration
Versions: < 0.5.10

Ranked PoCs (2) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-07-15T00:00:20.000Z · profiled 2026-07-15T00:30:20.000Z