CVE-2026-56782P1CRITICALCVSS 9.8PoCfixed in 0.5.102026-06-29
CVE-2026-56782 [CRITICAL] CWE-306 CVE-2026-56782: Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restor
Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints that allows unauthenticated attackers to access protected functionality when admin_api_key is empty, which is the default configuration. Remote attackers can exfiltrate the entire database including user records, items, and feedback data
nvd