Back

CRITICAL

pig before 4.1.0 Unverified Password Change via /register/password

Published Sep 15, 2026

Description

pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verification results are discarded, allowing any value as the current password. Remote attackers can submit a username with an incorrect current password to overwrite any account credential including the admin account and gain full administrative control.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Sep 15, 2026
Updated Sep 24, 2026
Reserved Sep 15, 2026
CISA Vulnrichment
Updated Sep 18, 2026
NVD
Status Received
Modified Sep 18, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner VulnCheck
Published Sep 15, 2026
Updated Sep 24, 2026
Exploited since n/a
EUVD-2026-78435