PatchSiren

sosedoff CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH sosedoff CVE published 2026-09-15

CVE-2026-91924

CVE-2026-91924 is a high-severity vulnerability in pgweb, a PostgreSQL database web interface. The vulnerability allows attackers to bypass authorization and access unauthorized databases and internal services by providing a custom session identifier and connection URL. This issue arises from the unguarded POST /api/connect endpoint when connect-backend authorization is configured, enabling attackers to s [truncated]