{"id":"CVE-2026-91995","summary":"pig before 4.1.0 Unverified Password Change via /register/password","details":"pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verification results are discarded, allowing any value as the current password. Remote attackers can submit a username with an incorrect current password to overwrite any account credential including the admin account and gain full administrative control.","modified":"2026-09-26T08:04:18.243446Z","published":"2026-09-15T11:35:50.060Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/91xxx/CVE-2026-91995.json","cna_assigner":"VulnCheck","cwe_ids":["CWE-620"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/91xxx/CVE-2026-91995.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91995"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/pig-before-4.1.0-unverified-password-change-via-register-password"},{"type":"REPORT","url":"https://github.com/pig-mesh/pig/issues/1249"},{"type":"FIX","url":"https://github.com/pig-mesh/pig/commit/ce958668f399110b97b3f1fcc5f517ff9bcfd535"},{"type":"PACKAGE","url":"https://github.com/pig-mesh/pig"},{"type":"ARTICLE","url":"https://github.com/pig-mesh/pig/blob/v4.0.0/pig-upms/pig-upms-biz/src/main/java/com/pig4cloud/pig/admin/controller/SysRegisterController.java#L21-L53"},{"type":"ARTICLE","url":"https://github.com/pig-mesh/pig/blob/v4.0.0/pig-upms/pig-upms-biz/src/main/java/com/pig4cloud/pig/admin/service/impl/SysUserServiceImpl.java#L650-L669"},{"type":"EVIDENCE","url":"https://github.com/geo-chen/oss/blob/main/pig.md"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pig-mesh/pig","events":[{"introduced":"0"},{"fixed":"f4e5a3a4b902dc00c192b878d7587cec93698803"},{"fixed":"ce958668f399110b97b3f1fcc5f517ff9bcfd535"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"4.1.0"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["v4.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-91995.json","vanir_signatures_modified":"2026-09-26T08:04:18Z","vanir_signatures":[{"id":"CVE-2026-91995-809595ca","signature_type":"Function","signature_version":"v1","source":"https://github.com/pig-mesh/pig/commit/ce958668f399110b97b3f1fcc5f517ff9bcfd535","target":{"file":"pig-upms/pig-upms-biz/src/main/java/com/pig4cloud/pig/admin/service/impl/SysUserServiceImpl.java","function":"resetUserPassword"},"deprecated":false,"digest":{"function_hash":"86967028468094647310072183449012952871","length":722}},{"target":{"file":"pig-upms/pig-upms-biz/src/main/java/com/pig4cloud/pig/admin/service/impl/SysUserServiceImpl.java"},"deprecated":false,"digest":{"line_hashes":["336908560957029207314149664835660236932","28617180692158646986847938000905869805","28378234866036317202458895008898397328","55988747771618724117785398882637786846","284158032370035268077165057903688546447","142978052920094040166815302129692700453"],"threshold":0.9},"id":"CVE-2026-91995-e22250f7","signature_type":"Line","signature_version":"v1","source":"https://github.com/pig-mesh/pig/commit/ce958668f399110b97b3f1fcc5f517ff9bcfd535"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}