HIGH
sosedoff
CVE published 2026-09-15
CVE-2026-91924
CVE-2026-91924 is a high-severity vulnerability in pgweb, a PostgreSQL database web interface. The vulnerability allows attackers to bypass authorization and access unauthorized databases and internal services by providing a custom session identifier and connection URL. This issue arises from the unguarded POST /api/connect endpoint when connect-backend authorization is configured, enabling attackers to s [truncated]