<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:pangolin:pangolin:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3apangolinpangolin/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 31 Aug 2026 19:58:46 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3apangolinpangolin/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass Vulnerability in Pangolin</title><link>https://feed.craftedsignal.io/briefs/2026-08-pangolin-auth-bypass/</link><pubDate>Mon, 31 Aug 2026 19:58:46 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-pangolin-auth-bypass/</guid><description>Pangolin versions prior to 1.22.0 are vulnerable to an authentication bypass in the share-link endpoint, allowing unauthenticated access to arbitrary resources.</description><content:encoded><![CDATA[<p>Pangolin versions prior to 1.22.0 contain a critical authentication bypass vulnerability (CVE-2026-72001) within the application's share-link authentication mechanism. This flaw stems from improper input validation during the token verification process. Specifically, the share-link authentication endpoint fails to enforce the inclusion of the resource identifier in the verification call, allowing an attacker to manipulate URL parameters to gain unauthorized access to protected content. By utilizing a single valid share link - which can be obtained for any low-security resource - an attacker can bypass all configured authentication controls, including SSO, resource passwords, PIN requirements, email allowlists, and header-based authentication. This allows for unauthorized traversal and access to arbitrary resources across different organizations within the Pangolin ecosystem. The vulnerability is rated with a CVSS 3.1 base score of 8.1, indicating high risk for organizations relying on Pangolin for secure document or resource sharing.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-72001 grants unauthenticated attackers the ability to access any resource managed by the Pangolin platform. This potential exposure includes sensitive proprietary information, internal documents, and collaborative data protected by organizational security policies. Because the vulnerability bypasses SSO and other robust authentication layers, organizations are at immediate risk of large-scale data exfiltration and unauthorized information disclosure across multi-tenant environments.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade Pangolin to version 1.22.0 or later immediately to address the vulnerability in the share-link authentication endpoint.</li>
<li>Audit access logs for the share-link endpoints for anomalous query patterns where the resource identifier is missing or mismatched from the expected token payload.</li>
<li>Disable public share links for highly sensitive resources until the patch is applied.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>authentication-bypass</category><category>cve-2026-72001</category><category>vulnerability</category></item></channel></rss>