CVE-2026-108157
Deferred Deferred - Pending Action

Improper Authentication in Pingvin Share X via OAuth Misconfiguration

Vulnerability report for CVE-2026-108157, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: VulnCheck

Description

Pingvin Share X from 0.19.0 before 1.22.0 contains an improper authentication vulnerability that allows remote unauthenticated attackers to take over accounts by abusing automatic OAuth email linking in OAuthService.signUp(). Attackers can register a victim's unverified email on an enabled OAuth/OIDC provider, exploiting the missing email_verified check in GenericOidcProvider, to sign in as the victim including administrators while bypassing TOTP.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
smp46 pingvin-share-x 0.19.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-108157 is an improper authentication vulnerability in Pingvin Share X versions 0.19.0 to 1.22.0-beta.0. It allows remote attackers to hijack user accounts by exploiting automatic OAuth email linking. Attackers register a victim's unverified email on an OAuth/OIDC provider and sign in as the victim, bypassing password checks and TOTP protections. The flaw stems from missing email_verified validation in GenericOidcProvider.

Detection Guidance

To detect this vulnerability, check if your Pingvin Share X instance is running a vulnerable version (0.19.0 to 1.22.0-beta.0). Inspect the OAuth/OIDC configuration for automatic email linking without email_verified validation. Review logs for suspicious OAuth sign-ins or account takeovers.

Impact Analysis

This vulnerability allows attackers to take over any user account, including administrators, without knowing passwords. They can access sensitive files, delete shares, or impersonate users. Even TOTP protections are bypassed. The impact includes data breaches, unauthorized access, and potential system compromise.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA due to unauthorized access to personal data. GDPR requires proper authentication and data protection; this flaw enables breaches. HIPAA mandates secure access controls; account takeover risks non-compliance. Organizations using affected versions must patch to avoid regulatory penalties.

Mitigation Strategies
  • Upgrade Pingvin Share X to version 1.22.0 or later immediately to patch the vulnerability.
  • Disable automatic OAuth account linking in the application settings if possible.
  • Manually verify email addresses for all OAuth/OIDC users to prevent unverified email hijacking.
  • Monitor for unauthorized account access or suspicious OAuth sign-ins in logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108157. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart