Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows an attacker who has obtained a valid username and password to skip the second-factor authentication (TOTP) requirement entirely. Although, an attacker still needs the user's password to reach this stage. This vulnerability is fixed in 1.16.3.
Metrics
Affected Vendors & Products
References
History
Tue, 12 May 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows an attacker who has obtained a valid username and password to skip the second-factor authentication (TOTP) requirement entirely. Although, an attacker still needs the user's password to reach this stage. This vulnerability is fixed in 1.16.3. | |
| Title | Pingvin Share X: TOTP Authentication Bypass via Password-only Login | |
| Weaknesses | CWE-287 CWE-697 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-12T17:40:28.894Z
Reserved: 2026-05-05T15:13:47.570Z
Link: CVE-2026-44196
No data.
Status : Received
Published: 2026-05-12T18:17:29.730
Modified: 2026-05-12T18:17:29.730
Link: CVE-2026-44196
No data.
OpenCVE Enrichment
Updated: 2026-05-12T19:45:15Z