Critical Authentication Bypass Vulnerability in Gorse Exposed
ID: 14e83cba-02e8-5243-b4e2-af6c339380d8
STIX ID: report--14e83cba-02e8-5243-b4e2-af6c339380d8
Feed Name: ThreatCluster
Threat Score
Critical authentication bypass (CVE-2026-56782) affects Gorse < 0.5.10: the /api/dump and /api/restore endpoints can be accessed without authentication if admin_api_key is left empty (default), enabling full database exfiltration or overwrite; a proof-of-concept was published on June 30, 2026, and mitigation is to upgrade to 0.5.10+ and set a strong admin_api_key—no active exploitation reported in the document.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
