Skip to content
Threat Feed
high advisory

Improper Authentication Vulnerability in Pingvin Share

Pingvin Share versions 0.19.0 through 1.21.x contain an authentication bypass vulnerability (CVE-2026-108157) allowing attackers to perform account takeover by exploiting improper email verification during OAuth registration.

CVE search metadata

CVE search record: CVE-2026-108157. Severity: high. CVSS: 8.1. KEV: no. Product: Pingvin Share (0.19.0 <= version < 1.22.0). Brief: Improper Authentication Vulnerability in Pingvin Share. Brief link: https://feed.craftedsignal.io/briefs/2026-10-pingvin-share-auth-bypass/

Pingvin Share versions 0.19.0 through 1.21.x are affected by an improper authentication vulnerability, tracked as CVE-2026-108157. The vulnerability exists within the OAuthService.signUp() function and the GenericOidcProvider, where the application fails to validate the email_verified claim when performing OAuth or OpenID Connect (OIDC) registrations. A remote, unauthenticated attacker can exploit this flaw by registering an arbitrary email address associated with an enabled OAuth/OIDC provider. By doing so, the attacker can associate their own OIDC registration with a victim's email address, effectively taking over the victim's account. This method bypasses existing password protections and Multi-Factor Authentication (MFA) requirements, including TOTP. Because administrative accounts can be targeted, this vulnerability presents a critical risk for unauthorized access and administrative control over the Pingvin Share instance.

Impact

Successful exploitation allows for full account takeover of any user within the target Pingvin Share instance, including administrative accounts. Attackers can bypass all secondary authentication mechanisms, including TOTP, leading to potential data exfiltration, unauthorized file sharing, and full administrative configuration control of the application.

Recommendation

  1. Upgrade Pingvin Share to version 1.22.0 or later immediately to address CVE-2026-108157.
  2. Audit user account modifications and unexpected OAuth provider associations within the application logs for activity matching account registration timeframes.
  3. Temporarily disable OIDC/OAuth registration if immediate patching is not possible and monitor application access logs for unusual registration patterns.

Immediate actions

Upgrade Pingvin Share to 1.22.0 or later

IT Operations 24h

Mitigations

Upgrade to Pingvin Share 1.22.0

immediate IT Operations

CVE-2026-108157