{"id":"CVE-2026-59148","aliases":["GHSA-rqx4-3f6q-3x2v"],"url":"https://o3.security/vulnerability/CVE-2026-59148","summary":"Mockoon: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft","details":"Mockoon provides way to design and run mock APIs. Prior to 9.7.0, Mockoon's admin API in commons-server/src/libs/server/admin-api.ts is mounted on the same Express listener as user-defined mock routes, enabled by default in shipped runtimes, serves Access-Control-Allow-Origin: * with write methods allowed, and has no authentication. Any unauthenticated caller who can reach the mock server port can read MOCKOON_* environment variables, write arbitrary process environment variables through /mockoon-admin/env-vars, rewrite mock route bodies, statuses, and headers through PUT /mockoon-admin/environment, read transaction logs and SSE streams, and purge state. This issue is fixed in version 9.7.0.","published":"2026-07-09T18:27:18.579Z","modified":"2026-08-12T03:51:35.968619632Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":{"score":0.00173,"percentile":0.07095,"asOf":"2026-08-21"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":{"url":"https://github.com/mockoon/mockoon/commit/c420b5a56918475b8663977b51e5f986e45b3299","label":"mockoon/mockoon@c420b5a"},"references":[{"type":"WEB","url":"https://github.com/mockoon/mockoon/releases/tag/v9.7.0"},{"type":"WEB","url":"https://mockoon.com/releases/9.7.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59148.json"},{"type":"ADVISORY","url":"https://github.com/mockoon/mockoon/security/advisories/GHSA-rqx4-3f6q-3x2v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59148"},{"type":"FIX","url":"https://github.com/mockoon/mockoon/commit/c420b5a56918475b8663977b51e5f986e45b3299"},{"type":"FIX","url":"https://github.com/mockoon/mockoon/pull/2254"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:35.968619632Z"}}