CVE-2026-56782: Missing Authentication for Critical Function in gorse-io gorse
Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints that allows unauthenticated attackers to access protected functionality when admin_api_key is empty, which is the default configuration. Remote attackers can exfiltrate the entire database including user records, items, and feedback data containing personally identifiable information, or completely overwrite the dataset without authentication.
AI Analysis
Technical Summary
Gorse before version 0.5.10 contains a critical authentication bypass vulnerability affecting the /api/dump and /api/restore endpoints. When the admin_api_key configuration is empty (default), unauthenticated remote attackers can bypass authentication controls to access protected functionality. This enables attackers to exfiltrate the entire database, including user records, items, and feedback data with personally identifiable information, or to overwrite the dataset entirely without any authentication. The vulnerability has a CVSS 4.0 score of 9.3, reflecting high impact and ease of exploitation. No official patch or remediation level is currently documented in the vendor advisory or CVE data.
Potential Impact
The vulnerability allows unauthenticated remote attackers to fully access and manipulate the database via the /api/dump and /api/restore endpoints if the admin_api_key is unset (empty). This can lead to complete data exfiltration of sensitive user and feedback information or total data overwrite, resulting in data loss and privacy breaches. The critical CVSS score (9.3) indicates a severe impact on confidentiality, integrity, and availability of the affected system.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should ensure the admin_api_key configuration is set to a strong, non-empty value to prevent unauthorized access to the /api/dump and /api/restore endpoints. Restrict network access to these endpoints to trusted administrators only. Monitor vendor channels for updates regarding an official patch or fix.
CVE-2026-56782: Missing Authentication for Critical Function in gorse-io gorse
Description
Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints that allows unauthenticated attackers to access protected functionality when admin_api_key is empty, which is the default configuration. Remote attackers can exfiltrate the entire database including user records, items, and feedback data containing personally identifiable information, or completely overwrite the dataset without authentication.
CVSS v4.0
Score 9.3critical
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Gorse before version 0.5.10 contains a critical authentication bypass vulnerability affecting the /api/dump and /api/restore endpoints. When the admin_api_key configuration is empty (default), unauthenticated remote attackers can bypass authentication controls to access protected functionality. This enables attackers to exfiltrate the entire database, including user records, items, and feedback data with personally identifiable information, or to overwrite the dataset entirely without any authentication. The vulnerability has a CVSS 4.0 score of 9.3, reflecting high impact and ease of exploitation. No official patch or remediation level is currently documented in the vendor advisory or CVE data.
Potential Impact
The vulnerability allows unauthenticated remote attackers to fully access and manipulate the database via the /api/dump and /api/restore endpoints if the admin_api_key is unset (empty). This can lead to complete data exfiltration of sensitive user and feedback information or total data overwrite, resulting in data loss and privacy breaches. The critical CVSS score (9.3) indicates a severe impact on confidentiality, integrity, and availability of the affected system.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should ensure the admin_api_key configuration is set to a strong, non-empty value to prevent unauthorized access to the /api/dump and /api/restore endpoints. Restrict network access to these endpoints to trusted administrators only. Monitor vendor channels for updates regarding an official patch or fix.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-06-23T01:24:27.650Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a42b42727e9c7971940f829
Added to database: 06/29/2026, 18:06:31 UTC
Last enriched: 07/15/2026, 10:17:25 UTC
Last updated: 08/13/2026, 12:41:11 UTC
Views: 91
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.