{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/pangolin/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:pangolin:pangolin:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-72001"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Pangolin (\u003c 1.22.0)"],"_cs_severities":["high"],"_cs_tags":["authentication-bypass","cve-2026-72001","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Pangolin"],"content_html":"\u003cp\u003ePangolin versions prior to 1.22.0 contain a critical authentication bypass vulnerability (CVE-2026-72001) within the application's share-link authentication mechanism. This flaw stems from improper input validation during the token verification process. Specifically, the share-link authentication endpoint fails to enforce the inclusion of the resource identifier in the verification call, allowing an attacker to manipulate URL parameters to gain unauthorized access to protected content. By utilizing a single valid share link - which can be obtained for any low-security resource - an attacker can bypass all configured authentication controls, including SSO, resource passwords, PIN requirements, email allowlists, and header-based authentication. This allows for unauthorized traversal and access to arbitrary resources across different organizations within the Pangolin ecosystem. The vulnerability is rated with a CVSS 3.1 base score of 8.1, indicating high risk for organizations relying on Pangolin for secure document or resource sharing.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-72001 grants unauthenticated attackers the ability to access any resource managed by the Pangolin platform. This potential exposure includes sensitive proprietary information, internal documents, and collaborative data protected by organizational security policies. Because the vulnerability bypasses SSO and other robust authentication layers, organizations are at immediate risk of large-scale data exfiltration and unauthorized information disclosure across multi-tenant environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Pangolin to version 1.22.0 or later immediately to address the vulnerability in the share-link authentication endpoint.\u003c/li\u003e\n\u003cli\u003eAudit access logs for the share-link endpoints for anomalous query patterns where the resource identifier is missing or mismatched from the expected token payload.\u003c/li\u003e\n\u003cli\u003eDisable public share links for highly sensitive resources until the patch is applied.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-31T19:58:46Z","date_published":"2026-08-31T19:58:46Z","id":"https://feed.craftedsignal.io/briefs/2026-08-pangolin-auth-bypass/","summary":"Pangolin versions prior to 1.22.0 are vulnerable to an authentication bypass in the share-link endpoint, allowing unauthenticated access to arbitrary resources.","title":"Authentication Bypass Vulnerability in Pangolin","url":"https://feed.craftedsignal.io/briefs/2026-08-pangolin-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Pangolin","version":"https://jsonfeed.org/version/1.1"}