PT-2026-56906 · Mockoon · Mockoon
CVE-2026-59148
·
Published
2026-07-09
·
Updated
2026-09-11
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Mockoon versions prior to 9.7.0
Description
The admin API in
commons-server/src/libs/server/admin-api.ts is mounted on the same Express listener as user-defined mock routes and is enabled by default in shipped runtimes. The API lacks authentication and serves Access-Control-Allow-Origin: * with write methods allowed. An unauthenticated caller with access to the mock server port can read MOCKOON * environment variables, write arbitrary process environment variables via the /mockoon-admin/env-vars endpoint, rewrite mock route bodies, statuses, and headers through the PUT /mockoon-admin/environment endpoint, read transaction logs and SSE (Server-Sent Events) streams, and purge state.Recommendations
Update to version 9.7.0.
Exploit
Fix
Incorrect Permission
CSRF
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mockoon