Improper Authentication Vulnerability in Pingvin Share X by smp46
CVE-2026-108157
9.2CRITICAL
What is CVE-2026-108157?
Pingvin Share X versions prior to 1.22.0 are susceptible to an improper authentication vulnerability that enables remote, unauthenticated attackers to seize user accounts. This is achieved by exploiting the automatic OAuth email linking mechanism within the OAuthService.signUp() function. Attackers can register a victim's unverified email through a vulnerable OAuth/OIDC provider, bypassing the necessary email verification check. This flaw allows malicious users to log in as the victim, including administrator accounts, without the need for two-factor authentication (TOTP), significantly compromising the integrity of the affected system.
Affected Version(s)
pingvin-share-x 0.19.0 < 1.22.0
