<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Pig (&lt; 4.1.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/pig--4.1.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 15 Sep 2026 13:40:26 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/pig--4.1.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass in pig via Password Reset Endpoint</title><link>https://feed.craftedsignal.io/briefs/2026-09-pig-auth-bypass/</link><pubDate>Tue, 15 Sep 2026 13:40:26 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-pig-auth-bypass/</guid><description>An authentication bypass vulnerability in pig versions prior to 4.1.0 allows remote attackers to perform unauthorized account takeovers by exploiting improper password verification in the /register/password endpoint.</description><content:encoded><![CDATA[<p>The pig application, in versions prior to 4.1.0, is affected by a critical authentication bypass vulnerability located in the /register/password endpoint. The vulnerability stems from the application discarding the results of the password verification process during the account credential update flow. Consequently, an attacker can supply an arbitrary value as the current password, bypass the validation check, and successfully overwrite the credentials for any user account, including administrative accounts. This flaw provides remote attackers with an unauthenticated path to achieve full administrative control over the affected application. Because the vulnerability allows for complete account takeover, it poses a significant risk to the integrity and confidentiality of the environment hosting the pig service.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows remote attackers to gain full administrative access to the pig application. This can lead to complete loss of account control, unauthorized access to sensitive application data, and the potential for further lateral movement if the application is integrated with other enterprise systems.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security teams:</p>
<ul>
<li>Patch the pig application to version 4.1.0 or later immediately to remediate CVE-2026-91995.</li>
<li>Review web server access logs for any POST requests directed to the /register/password endpoint that correlate with suspicious administrative account changes or unexpected password resets.</li>
<li>Audit existing administrative accounts for unauthorized modifications or newly created entries that align with the timeline of potential exploitation.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>