SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-91995

CRITICAL · CVSS 9.1 EPSS 0.61% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

An authentication bypass vulnerability exists in versions of Pig prior to 4.1.0, specifically in the /register/password endpoint, where password verification is improperly handled. This flaw allows remote attackers to overwrite any account credentials, including those of administrative accounts, leading to full administrative control over the affected systems. Organizations using vulnerable versions of Pig should prioritize immediate updates to mitigate the risk of unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-91995
Severity
CRITICAL
CVSS
9.1
EPSS
0.61%

Original NVD Description

pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verification results are discarded, allowing any value as the current password. Remote attackers can submit a username with an incorrect current password to overwrite any account credential including the admin account and gain full administrative control.