Description
pgweb through 0.17.0 leaves the POST /api/connect endpoint unguarded when connect-backend authorization is configured, allowing attackers to supply arbitrary database connection strings. Attackers can bypass the resource-to-database mapping by providing a custom session identifier and connection URL to access unauthorized databases and internal services.
Published: 2026-09-15
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Database Access
Action: Patch Now
AI Analysis

Impact

pgweb through 0.17.0 allows an attacker to send an unauthenticated POST request to /api/connect when connection‑backend authorization is active. The request can carry any database connection string and a custom session identifier, bypassing the intended resource‑to‑database mapping. As a result the attacker can gain access to databases and internal services that should be protected, potentially exposing confidential data or executing malicious queries.

Affected Systems

This issue affects the pgweb web‑based database manager developed by sosedoff, specifically releases up through and including version 0.17.0. Any instance running this version without proper network isolation is vulnerable.

Risk and Exploitability

The vulnerability scores a CVSS of 8.4, indicating high severity, and its EPSS score is below 1 %. The lack of authentication on the endpoint provides a direct remote exploitation path: any host that can reach the pgweb service can send the malicious request. The issue is not listed in the CISA KEV catalog, but if an instance is exposed to untrusted networks the impact can be significant.

Generated by OpenCVE AI on September 17, 2026 at 16:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest pgweb release that contains the authorization fix, which addresses the missing authorization issue (CWE-862).
  • Ensure that the pgweb instance is only reachable to limit exposure.
  • Implement network‑level controls or firewall rules to block or monitor unauthorized POST /api/connect requests, mitigating the risk of unauthorized database access (CWE-862).

Generated by OpenCVE AI on September 17, 2026 at 16:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Sosedoff
Sosedoff pgweb
Vendors & Products Sosedoff
Sosedoff pgweb

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Description pgweb through 0.17.0 leaves the POST /api/connect endpoint unguarded when connect-backend authorization is configured, allowing attackers to supply arbitrary database connection strings. Attackers can bypass the resource-to-database mapping by providing a custom session identifier and connection URL to access unauthorized databases and internal services.
Title pgweb through 0.17.0 Missing Authorization on Direct Connect Endpoint
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:29.786Z

Reserved: 2026-09-15T10:42:44.016Z

Link: CVE-2026-91924

cve-icon Vulnrichment

Updated: 2026-09-17T14:22:16.215Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T11:17:13.053

Modified: 2026-09-23T17:17:44.827

Link: CVE-2026-91924

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:15:13Z

Weaknesses