CPE
Pangolin versions prior to 1.22.0 are vulnerable to an authentication bypass in the share-link endpoint, allowing unauthenticated access to arbitrary resources.