Product
Pingvin Share versions 0.19.0 through 1.21.x contain an authentication bypass vulnerability (CVE-2026-108157) allowing attackers to perform account takeover by exploiting improper email verification during OAuth registration.