CVE-2026-56782Patch

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints that allows unauthenticated attackers to access protected functionality when admin_api_key is empty, which is the default configuration. Remote attackers can exfiltrate the entire database including user records, items, and feedback data containing personally identifiable information, or completely overwrite the dataset without authentication.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-07-04)
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-06-29: 1Mentions · 2026-06-30: 1Mentions · 2026-07-04: 2Patch / Workaround · 2026-06-29: 1Patch / Workaround · 2026-06-30: 1Patch / Workaround · 2026-07-04: 1Technical Details · 2026-06-29: 1Technical Details · 2026-06-30: 1Technical Details · 2026-07-04: 206-2906-3007-04
Signal classification3 categories
Patch
250.0%
Disclosure
125.0%
General
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-06-291
Patch1
2026-06-301
Disclosure1
2026-07-042
General1Patch1
Full discourse4 posts
  • pdnuclei-bot@pdnuclei_bot
    General

    🚨 CVE-2026-56782 - critical 🚨 Gorse < 0.5.10 - Unauthenticated Database Dump > Gorse < 0.5.10 contains an authentication bypass caused by empty admin_api_key in /ap... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-56782 @pdnuclei #NucleiTemplates #cve

    Post summary

    CVE-2026-56782 presents a critical unauth thông xác: unauthenticated database dump due to authentication bypass in Gorse < 0.5.10, with no reported exploitation, patch, or PoC details.

    00002382
    973 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-56782 — CVSS 9.8/10 ██████████ Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints that... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/g0lTzgMluF

    Post summary

    Critical authentication bypass vulnerability (CVE-2026-56782) affecting Gorse versions before 0.5.10—patched now.

    1000070
    62 followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    🗄️ No auth? No problem (for attackers). CVE-2026-56782 in Gorse allows unauthenticated DB dump AND restore via /api/dump and /api/restore. Full data theft or poisoning. Upgrade to 0.5.10 now. #AppSec #CVE https://secalerts.co/vulnerability/CVE-2026-56782?utm_campaign=x https://t.co/pWUHSlLjRL

    Post summary

    The tweet announces CVE‑2026‑56782, detailing unauthenticated database dump and restore via specific API endpoints, and urges users to upgrade to version 0.5.10 to remediate the issue.

    00000142
    847 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - Gorse admin API auth bypass via empty admin_api_key (CVE-2026-56782) Gorse before 0.5.10 contains an authentication bypass in its HTTP API, specifically the /api/dump and /api/restore endpoints when admin_api_key is left empty (default). The root cause is improper authentication/input validation that treats an empty admin_api_key as effectively disabling access control for admin-only routes. An attacker can exploit this remotely over the network with no credentials by directly calling these endpoints on exposed instances where the admin API key was never set. Impact is severe: full database dump including user records/PII (data exfiltration) and unauthorized dataset overwrite via restore, enabling data tampering and service compromise. 👉 Affected: gorse < 0.5.10 | Upgrade to 0.5.10

    Post summary

    An authentication bypass in Gorse’s admin API allows attackers to dump or restore data without credentials; the issue is fixed in version 0.5.10.

    0000057
    232 followersView on X

Explore more