pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verification results are discarded, allowing any value as the current password. Remote attackers can submit a username with an incorrect current password to overwrite any account credential including the admin account and gain full administrative control.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 15 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verification results are discarded, allowing any value as the current password. Remote attackers can submit a username with an incorrect current password to overwrite any account credential including the admin account and gain full administrative control.
Title pig before 4.1.0 Unverified Password Change via /register/password
Weaknesses CWE-620
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T11:35:50.060Z

Reserved: 2026-09-15T11:11:13.312Z

Link: CVE-2026-91995

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-15T12:17:54.943

Modified: 2026-09-15T12:17:54.943

Link: CVE-2026-91995

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses