# CVE-2026-91924

## Summary

- **CVE ID:** CVE-2026-91924
- **Severity:** HIGH
- **CVSS Score:** 8.5 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N)
- **CWE:** CWE-862
- **Published:** Sep 15, 2026
- **Last Modified:** Sep 15, 2026

## Description

pgweb through 0.17.0 leaves the POST /api/connect endpoint unguarded when connect-backend authorization is configured, allowing attackers to supply arbitrary database connection strings. Attackers can bypass the resource-to-database mapping by providing a custom session identifier and connection URL to access unauthorized databases and internal services.

## Affected Products

- sosedoff — pgweb (0)

## References

- [CNA](https://github.com/sosedoff/pgweb/issues/869)
- [CNA](https://github.com/sosedoff/pgweb)
- [CNA](https://github.com/sosedoff/pgweb/blob/6b0b0244d1aefd6971999b03481eeeaa4ec7cf55/pkg/api/routes.go)
- [CNA](https://github.com/sosedoff/pgweb/blob/6b0b0244d1aefd6971999b03481eeeaa4ec7cf55/pkg/api/api.go)
- [CNA](https://www.vulncheck.com/advisories/pgweb-through-0.17.0-missing-authorization-on-direct-connect-endpoint)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.25%
- **EPSS Percentile:** 16.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._