← Vulnerability feed

Vulnerability record · CVE-2026-91995 · published 15 September 2026

CVE-2026-91995: pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where pass…

pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verification results are discarded, allowing any value as the current password. Remote attackers can submit a username with an incorrect current password to overwrite any account credential including the admin account and gain full administrative control.

9.3 CVSS 4.0 Critical EPSS 0.88% · top 42.6% CWE-620 · CWE-620 Deferred
9.3CVSS 4.0 base score
0.88%EPSS exploitation probability, 30 days
NoNot in CISA KEV
0Affected product versions listed by NVD
7References
24 Sep 2026Last modified by NVD

Description

pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verification results are discarded, allowing any value as the current password. Remote attackers can submit a username with an incorrect current password to overwrite any account credential including the admin account and gain full administrative control.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

References

Track CVE-2026-91995 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2026-91995), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.