Impact
An authentication bypass exists in the /register/password endpoint of pig before 4.1.0. The service discards the result of password verification, allowing any value as the current password. Remote attackers can submit a username with an incorrect current password and overwrite the target of the admin account. This gives the attacker full administrative control overThe vulnerability affects the pig-mesh pig application, specifically all releases prior to version 4.1.0. Identified references include source code and issue discussion for the 4.0.0 release, indicating the problem exists in that version and earlier.
Affected Systems
pig-mesh pig, all releases before version 4.1.0
Risk and Exploitability
The CVSS score of 9.3 reflects the critical nature of the flaw. The EPSS score of <1% indicates a low probability of exploitation, but the endpoint is publicly accessible, and exploitation remains plausible. The vulnerability is not yet listed in the CISA KEV catalog, however the potential for complete administrative takeover warrants immediate attention. Attackers would need knowledge of a valid username and the ability to reach the /register/password endpoint, after which the authentication bypass enables credential overwrite.
OpenCVE Enrichment