{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/pgweb--0.17.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:pgweb_project:pgweb:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.5,"id":"CVE-2026-91924"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["pgweb (\u003c= 0.17.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","web-application","authentication-bypass"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003epgweb versions up to and including 0.17.0 contain a critical vulnerability in the POST /api/connect endpoint. When the connect-backend authorization configuration is enabled, the application fails to enforce appropriate access controls. This flaw allows an unauthenticated attacker to supply a custom session identifier and an arbitrary database connection URL. By manipulating these parameters, an attacker can bypass the intended resource-to-database mapping logic and gain unauthorized access to internal database services or other sensitive endpoints that the pgweb instance is capable of reaching. This vulnerability represents a significant risk for environments deploying pgweb as a database management interface, as it effectively allows server-side request forgery (SSRF) and unauthorized data access.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to interact with arbitrary databases, potentially leading to unauthorized data exfiltration, modification, or exposure of sensitive internal infrastructure that would otherwise be shielded by the application's authorization layer. Given the nature of the application, this access often provides a foothold for further lateral movement within internal network segments where database servers are hosted.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all instances of pgweb to a version beyond 0.17.0 immediately.\u003c/li\u003e\n\u003cli\u003eImplement network-level access control lists (ACLs) to restrict access to the pgweb /api/connect endpoint to authorized management workstations only.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to monitor for suspicious POST requests to the /api/connect endpoint that deviate from established baselines.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-15T11:40:04Z","date_published":"2026-09-15T11:40:04Z","id":"https://feed.craftedsignal.io/briefs/2026-09-pgweb-auth-bypass/","summary":"An authorization bypass vulnerability in pgweb versions up to 0.17.0 allows unauthenticated attackers to supply arbitrary connection strings via the /api/connect endpoint.","title":"Authorization Bypass in pgweb API Connect Endpoint","url":"https://feed.craftedsignal.io/briefs/2026-09-pgweb-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Pgweb (\u003c= 0.17.0)","version":"https://jsonfeed.org/version/1.1"}