pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verification results are discarded, allowing any value as the current password. Remote attackers can submit a username with an incorrect current password to overwrite any account credential including the admin account and gain full administrative control.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-620"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/91xxx/CVE-2026-91995.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-91995.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "86967028468094647310072183449012952871",
"length": 722
},
"id": "CVE-2026-91995-809595ca",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/pig-mesh/pig/commit/ce958668f399110b97b3f1fcc5f517ff9bcfd535",
"target": {
"file": "pig-upms/pig-upms-biz/src/main/java/com/pig4cloud/pig/admin/service/impl/SysUserServiceImpl.java",
"function": "resetUserPassword"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"336908560957029207314149664835660236932",
"28617180692158646986847938000905869805",
"28378234866036317202458895008898397328",
"55988747771618724117785398882637786846",
"284158032370035268077165057903688546447",
"142978052920094040166815302129692700453"
],
"threshold": 0.9
},
"id": "CVE-2026-91995-e22250f7",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/pig-mesh/pig/commit/ce958668f399110b97b3f1fcc5f517ff9bcfd535",
"target": {
"file": "pig-upms/pig-upms-biz/src/main/java/com/pig4cloud/pig/admin/service/impl/SysUserServiceImpl.java"
}
}
]
"2026-09-26T08:04:18Z"