Description
pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verification results are discarded, allowing any value as the current password. Remote attackers can submit a username with an incorrect current password to overwrite any account credential including the admin account and gain full administrative control.
Published: 2026-09-15
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Administrative Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

An authentication bypass exists in the /register/password endpoint of pig before 4.1.0. The service discards the result of password verification, allowing any value as the current password. Remote attackers can submit a username with an incorrect current password and overwrite the target of the admin account. This gives the attacker full administrative control overThe vulnerability affects the pig-mesh pig application, specifically all releases prior to version 4.1.0. Identified references include source code and issue discussion for the 4.0.0 release, indicating the problem exists in that version and earlier.

Affected Systems

pig-mesh pig, all releases before version 4.1.0

Risk and Exploitability

The CVSS score of 9.3 reflects the critical nature of the flaw. The EPSS score of <1% indicates a low probability of exploitation, but the endpoint is publicly accessible, and exploitation remains plausible. The vulnerability is not yet listed in the CISA KEV catalog, however the potential for complete administrative takeover warrants immediate attention. Attackers would need knowledge of a valid username and the ability to reach the /register/password endpoint, after which the authentication bypass enables credential overwrite.

Generated by OpenCVE AI on September 17, 2026 at 17:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade pig to version 4.1.0 or later to receive the fix for the password verification bypass.
  • If an upgrade is not immediately feasible, restrict access to the /register/password endpoint to authenticated administrators only and enforce proper verification of the current password before allowing a change.
  • Review and test account change flows to confirm that the current password is validated and that no credential overwrite is possible.

Generated by OpenCVE AI on September 17, 2026 at 17:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Pig-mesh
Pig-mesh pig
Vendors & Products Pig-mesh
Pig-mesh pig

Tue, 15 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verification results are discarded, allowing any value as the current password. Remote attackers can submit a username with an incorrect current password to overwrite any account credential including the admin account and gain full administrative control.
Title pig before 4.1.0 Unverified Password Change via /register/password
Weaknesses CWE-620
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:34.732Z

Reserved: 2026-09-15T11:11:13.312Z

Link: CVE-2026-91995

cve-icon Vulnrichment

Updated: 2026-09-18T17:16:54.172Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T12:17:54.943

Modified: 2026-09-24T21:08:55.030

Link: CVE-2026-91995

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:15:13Z

Weaknesses
  • CWE-620

    Unverified Password Change