CVE-2026-44196 Details
Description
Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows an attacker who has obtained a valid username and password to skip the second-factor authentication (TOTP) requirement entirely. Although, an attacker still needs the user's password to reach this stage. This vulnerability is fixed in 1.16.3.
A critical authentication bypass vulnerability has been identified in Pingvin Share X versions 1.14.1 prior to 1.16.2. This vulnerability allows an attacker with a valid username and password to completely bypass the second-factor authentication requirement (TOTP). While the attacker must still possess the user's password to exploit this vulnerability, successfully doing so grants full access to the user's account, including the ability to manage shares, view sensitive files, and modify account settings. Given that Pingvin Share X supports unlimited file sizes and various storage providers like S3, the risk of data exposure is considerable.
Users are advised to update to Pingvin Share X version 1.16.3, where this vulnerability has been patched. For those using Watchtower, the update should occur automatically once the new image is pulled. If an immediate upgrade is not possible, consider disabling password-based logins and requiring authentication through OIDC or LDAP providers that manage their own two-factor authentication. Alternatively, restrict network access to the login portal via a VPN or IP allowlist until the patch can be applied.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 12, 2026CISA-ADP
Assessed May 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/smp46/pingvin-share-x/security/advisories/GHSA-j679-vp39-qwqq | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
| CWE-697 | Incorrect Comparison | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Pingvin Share X | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 12, 2026 | New CVE Received | [email protected] |
Volerion