Mockoon disclosed and fixed CVE-2026-59148, a high-severity flaw affecting versions before 9.7.0 that exposed its Admin API on the same Express listener as user-defined mock routes without authentication. Combined with wildcard CORS and permitted write methods, the issue allowed remote attackers who could reach the mock server port to read MOCKOON_* environment variables, alter mock route bodies, headers, and status codes, access transaction logs and SSE streams, and purge application state. The vulnerability carries a CVSS 8.8 rating and is tied to missing authentication, CSRF risk, improper permission controls, and permissive cross-domain policy weaknesses.
The fix shipped in Mockoon 9.7.0 through a broader Admin API security hardening update. The changes introduced mandatory bearer-token protection for the Admin API, support for --admin-api-token and MOCKOON_ADMIN_API_TOKEN, automatic secure token generation when none is supplied, configurable CORS allowlisting, and stricter controls on environment-variable writes so empty prefixes are rejected and arbitrary variable modification is blocked. The update also expanded redaction of sensitive headers and values in logs and Admin API responses, while documenting that the Admin API remains enabled by default at /mockoon-admin/ but can be disabled.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-09, CVE-2026-59148 was published describing a high-severity Mockoon vulnerability affecting versions prior to 9.7.0. The issue allowed remote attackers reaching the mock server port to access MOCKOON_* environment variables, alter mock routes and responses, view logs and SSE streams, and purge application state.
On 2026-06-18, Mockoon published release v9.7.0. Reference content indicates this version contains fixes for the exposed unauthenticated Admin API, permissive CORS behavior, and unsafe environment-variable handling.
On 2026-06-18, Mockoon merged pull request #2254 into main, adding bearer-token authentication for the Admin API, configurable CORS allowlisting, enforced environment-variable prefixing for admin writes, and broader redaction of sensitive values.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourcemockoon.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.