Improper Authentication Vulnerability in Pingvin Share X by smp46
CVE-2026-108157

9.2CRITICAL

Key Information:

Vendor

Smp46

Vendor
CVE Published:
9 October 2026

What is CVE-2026-108157?

Pingvin Share X versions prior to 1.22.0 are susceptible to an improper authentication vulnerability that enables remote, unauthenticated attackers to seize user accounts. This is achieved by exploiting the automatic OAuth email linking mechanism within the OAuthService.signUp() function. Attackers can register a victim's unverified email through a vulnerable OAuth/OIDC provider, bypassing the necessary email verification check. This flaw allows malicious users to log in as the victim, including administrator accounts, without the need for two-factor authentication (TOTP), significantly compromising the integrity of the affected system.

Affected Version(s)

pingvin-share-x 0.19.0 < 1.22.0

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Matéo Florian Callec
.