PT-2026-56906 · Mockoon · Mockoon

CVE-2026-59148

·

Published

2026-07-09

·

Updated

2026-09-11

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mockoon versions prior to 9.7.0
Description The admin API in commons-server/src/libs/server/admin-api.ts is mounted on the same Express listener as user-defined mock routes and is enabled by default in shipped runtimes. The API lacks authentication and serves Access-Control-Allow-Origin: * with write methods allowed. An unauthenticated caller with access to the mock server port can read MOCKOON * environment variables, write arbitrary process environment variables via the /mockoon-admin/env-vars endpoint, rewrite mock route bodies, statuses, and headers through the PUT /mockoon-admin/environment endpoint, read transaction logs and SSE (Server-Sent Events) streams, and purge state.
Recommendations Update to version 9.7.0.

Exploit

Fix

Incorrect Permission

CSRF

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59148
GHSA-RQX4-3F6Q-3X2V

Affected Products

Mockoon