CVE-2026-91995

LOW

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

0.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Deep dive

Full discourse1 post
  • Upwind Security MDR@UpwindMDR

    🚨Critical - pig Auth Bypass via /register/password Current-Password Check Discarded (CVE-2026-91995) pig's /register/password endpoint discards the current-password verification result, letting an unauthenticated attacker submit any username + any current password to overwrite that user's credentials (incl. admin). This enables full account takeover and admin control. 👉Affected: pig < 4.1.0 | Upgrade to 4.1.0

    0000036
    304 followersView on X

Explore more