{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3apig_projectpig/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:pig_project:pig:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-91995"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=CVE-2026-91995\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["pig (\u003c 4.1.0)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe pig application, in versions prior to 4.1.0, is affected by a critical authentication bypass vulnerability located in the /register/password endpoint. The vulnerability stems from the application discarding the results of the password verification process during the account credential update flow. Consequently, an attacker can supply an arbitrary value as the current password, bypass the validation check, and successfully overwrite the credentials for any user account, including administrative accounts. This flaw provides remote attackers with an unauthenticated path to achieve full administrative control over the affected application. Because the vulnerability allows for complete account takeover, it poses a significant risk to the integrity and confidentiality of the environment hosting the pig service.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows remote attackers to gain full administrative access to the pig application. This can lead to complete loss of account control, unauthorized access to sensitive application data, and the potential for further lateral movement if the application is integrated with other enterprise systems.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePatch the pig application to version 4.1.0 or later immediately to remediate CVE-2026-91995.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for any POST requests directed to the /register/password endpoint that correlate with suspicious administrative account changes or unexpected password resets.\u003c/li\u003e\n\u003cli\u003eAudit existing administrative accounts for unauthorized modifications or newly created entries that align with the timeline of potential exploitation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-15T15:31:32Z","date_published":"2026-09-15T13:40:26Z","id":"https://feed.craftedsignal.io/briefs/2026-09-pig-auth-bypass/","summary":"An authentication bypass vulnerability in pig versions prior to 4.1.0 allows remote attackers to perform unauthorized account takeovers by exploiting improper password verification in the /register/password endpoint.","title":"Authentication Bypass in pig via Password Reset Endpoint","url":"https://feed.craftedsignal.io/briefs/2026-09-pig-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:pig_project:pig:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}