Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 09 Oct 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Smp46
Smp46 pingvin-share-x |
|
| Vendors & Products |
Smp46
Smp46 pingvin-share-x |
Fri, 09 Oct 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pingvin Share X from 0.19.0 before 1.22.0 contains an improper authentication vulnerability that allows remote unauthenticated attackers to take over accounts by abusing automatic OAuth email linking in OAuthService.signUp(). Attackers can register a victim's unverified email on an enabled OAuth/OIDC provider, exploiting the missing email_verified check in GenericOidcProvider, to sign in as the victim including administrators while bypassing TOTP. | |
| Title | Pingvin Share X 0.19.0 before 1.22.0 Account Takeover via OAuth Email Linking | |
| Weaknesses | CWE-287 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-09T17:14:05.839Z
Reserved: 2026-10-09T15:41:44.132Z
Link: CVE-2026-108157
No data.
Status : Deferred
Published: 2026-10-09T17:16:46.703
Modified: 2026-10-09T17:41:47.060
Link: CVE-2026-108157
No data.
OpenCVE Enrichment
Updated: 2026-10-09T17:30:08Z
-
CWE-287
Improper Authentication