{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/mockoon/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:mockoon:mockoon:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-59148"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["commons-server (\u003c 9.7.0)","cli (\u003c 9.7.0)"],"_cs_severities":["high"],"_cs_tags":["webserver","vulnerability","cve"],"_cs_type":"advisory","_cs_vendors":["Mockoon"],"content_html":"\u003cp\u003eMockoon, a popular mock server tool, contains a critical security vulnerability in its admin API, which is enabled by default across all runtimes, including \u003ccode\u003e@mockoon/commons-server\u003c/code\u003e, the CLI, and serverless deployments. The admin API, located at \u003ccode\u003e/mockoon-admin/\u003c/code\u003e, lacks any form of authentication or authorization, allowing any unauthenticated user with network access to the server (defaulting to 0.0.0.0:3000) to manipulate the service. Furthermore, the API endpoints explicitly set \u003ccode\u003eAccess-Control-Allow-Origin: *\u003c/code\u003e, which permits browser-based attackers to interact with the admin API cross-origin via CSRF. This flaw allows an attacker to steal sensitive \u003ccode\u003eMOCKOON_*\u003c/code\u003e environment variables, inject arbitrary process-level environment variables (e.g., \u003ccode\u003eAWS_SECRET_ACCESS_KEY\u003c/code\u003e), rewrite mock API responses, and harvest sensitive data from transaction logs or Server-Sent Events (SSE). The vulnerability, tracked as CVE-2026-59148, affects all versions prior to 9.7.0.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs network reconnaissance to identify Mockoon instances running on default port 3000 or via local browser-based discovery.\u003c/li\u003e\n\u003cli\u003eAttacker interacts with \u003ccode\u003e/mockoon-admin/env-vars/\u003c/code\u003e endpoints via standard HTTP methods (GET/POST) without authentication to identify and exfiltrate secrets stored as \u003ccode\u003eMOCKOON_*\u003c/code\u003e variables.\u003c/li\u003e\n\u003cli\u003eAttacker uses \u003ccode\u003ePOST /mockoon-admin/env-vars/\u003c/code\u003e to inject or overwrite arbitrary process-level environment variables, potentially influencing the host runtime or subsequent SDK operations.\u003c/li\u003e\n\u003cli\u003eAttacker utilizes \u003ccode\u003ePUT /mockoon-admin/environment\u003c/code\u003e to rewrite mock configurations, modifying body contents, status codes, and HTTP headers of downstream mock routes.\u003c/li\u003e\n\u003cli\u003eAttacker leverages wildcard CORS headers to execute cross-origin requests from a malicious webpage, bypassing browser same-origin policies if the developer interacts with the site.\u003c/li\u003e\n\u003cli\u003eAttacker observes live traffic and sensitive client auth headers (e.g., Authorization tokens, Cookies) by querying \u003ccode\u003e/mockoon-admin/logs\u003c/code\u003e or subscribing to the SSE stream at \u003ccode\u003e/mockoon-admin/events\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFinal objective is achieved, ranging from credential theft and data exfiltration to complete supply-chain compromise via manipulated mock responses served to integration partners.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the theft of local development secrets, poisoning of production-like staging environments, and the modification of mock responses to inject malicious payloads into downstream testing or CI/CD pipelines. Exposure in CI/CD environments provides a pathway to steal cloud infrastructure credentials or perform man-in-the-middle attacks on internal development tools.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate all instances of \u003ccode\u003e@mockoon/cli\u003c/code\u003e and \u003ccode\u003e@mockoon/commons-server\u003c/code\u003e to version 9.7.0 or later immediately to patch CVE-2026-59148.\u003c/li\u003e\n\u003cli\u003eAudit CI/CD pipelines for exposed Mockoon services; ensure that if the admin API is not strictly required, it is disabled using the \u003ccode\u003e--disable-admin-api\u003c/code\u003e flag.\u003c/li\u003e\n\u003cli\u003eImplement network-level restrictions using firewall rules to limit access to the Mockoon admin port (default 3000) to only trusted management subnets.\u003c/li\u003e\n\u003cli\u003eScan for and rotate any environment variables that were hosted in Mockoon environments potentially accessible to unauthorized network traffic, particularly cloud provider keys and JWT secrets.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-12T00:57:28Z","date_published":"2026-09-12T00:57:28Z","id":"https://feed.craftedsignal.io/briefs/2026-09-mockoon-admin-hijack/","summary":"Mockoon versions before 9.7.0 expose an unauthenticated, CORS-misconfigured admin API by default, allowing attackers to exfiltrate environment variables, hijack mock responses, and perform cross-origin secret theft.","title":"Unauthenticated Admin API Exposure in Mockoon","url":"https://feed.craftedsignal.io/briefs/2026-09-mockoon-admin-hijack/"}],"language":"en","title":"CraftedSignal Threat Feed - Mockoon","version":"https://jsonfeed.org/version/1.1"}