Authentication Bypass Vulnerability in Pingvin Share X Affected Versions
CVE-2026-44196

9.1CRITICAL

Key Information:

Vendor

Smp46

Vendor
CVE Published:
12 May 2026

What is CVE-2026-44196?

Pingvin Share X, a self-hosted file sharing platform, has been identified with a vulnerability that allows an attacker, having acquired valid user credentials, to bypass the two-factor authentication (TOTP) process entirely. This security issue affects versions 1.14.1 through 1.16.2, exposing users to potential unauthorized access. The vulnerability is addressed and resolved in version 1.16.3.

Affected Version(s)

pingvin-share-x >= 1.14.1, < 1.16.3

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.