Summary
CVE-2026-56782 is a critical authentication bypass vulnerability (CWE-306: Missing Authentication for Critical Function) affecting Gorse, an open-source AI-powered recommender system engine, in all versions prior to 0.5.10. The flaw allows unauthenticated remote attackers to access the /api/dump and /api/restore endpoints without credentials whenever the admin_api_key configuration parameter is empty — which is the default out-of-box state. With a CVSS v3.1 score of 9.8 (Critical), this vulnerability poses a severe risk of full database exfiltration and data destruction against any publicly exposed Gorse instance running an unpatched version.
Technical details
- Root cause: The
/api/dumpand/api/restoreendpoints perform no authentication check when theadmin_api_keyconfiguration value is empty. Becauseadmin_api_keyis empty by default, no misconfiguration or special setup is required to trigger the vulnerability — the default installation is vulnerable. - Trigger condition: Any Gorse deployment running a version prior to 0.5.10 where
admin_api_keyhas not been explicitly set in the configuration file is exploitable without further prerequisites. - Attack vector: Network-accessible; no privileges, credentials, or user interaction are required. An attacker need only reach the Gorse API port over the internet.
- Impact via
/api/dump: Complete exfiltration of the Gorse database, including user records, item data, and feedback data that may contain personally identifiable information (PII). - Impact via
/api/restore: Complete overwrite of the dataset, enabling full destruction or poisoning of recommendation data and the underlying user/item corpus.
Affected software
- gorse-io/gorse — all versions prior to 0.5.10
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector String:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Patch: Upgrade to Gorse 0.5.10 or later. The fix is tracked in pull request #1294 ("Protect dump and restore endpoints") in the official repository.
- Workaround (if immediate patching is not possible): Explicitly set a strong, non-empty value for
admin_api_keyin the Gorse configuration file, and restrict network access to the Gorse API port using firewall rules or reverse-proxy authentication so it is not directly reachable from the internet.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

