Search Results (1 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-91924 1 Sosedoff 1 Pgweb 2026-09-17 8.5 High
pgweb through 0.17.0 leaves the POST /api/connect endpoint unguarded when connect-backend authorization is configured, allowing attackers to supply arbitrary database connection strings. Attackers can bypass the resource-to-database mapping by providing a custom session identifier and connection URL to access unauthorized databases and internal services.