CVE Feed

    Dashboard / CVE / CVE-2026-56782

    CVE-2026-56782

    Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints that allows unauthenticated attackers to access protected functionality when admin_api_key is empty, which is the default configuration. Remote attackers can exfiltrate the entire database including user records, items, and feedback data containing personally identifiable information, or completely overwrite the dataset without authentication.

    Published:Jun 29, 2026
    Last Modified:Jul 1, 2026
    EPS:Jun 29, 2026
    EPSS Score:0.00896
    CVSS Score:9.8

    Affected Products

    Vendor
    Gorse-io
    Product
    Gorse

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High