Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-56782: Gorse before 0.5.10 allows unauthorized access to sensitive data
CVE-2026-56782
CVE-2026-56782
Summary
The Gorse software has a security flaw that allows attackers to access and potentially steal or delete sensitive user data without being authorized. This is a concern because it could lead to a data breach. To fix this, update to version 0.5.10 or later.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| gorse-io | gorse | < 0.5.10 |
Original title
Gorse - Unauthenticated Database Dump and Restore via /api/dump and /api/restore Endpoints
Original description
Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints that allows unauthenticated attackers to access protected functionality when admin_api_key is empty, which is the default configuration. Remote attackers can exfiltrate the entire database including user records, items, and feedback data containing personally identifiable information, or completely overwrite the dataset without authentication.
nvd CVSS3.1
9.8
nvd CVSS4.0
9.3
Vulnerability type
CWE-306
Missing Authentication for Critical Function
Published: 29 Jun 2026 · Updated: 23 Jul 2026 · First seen: 29 Jun 2026