CVE-2026-108157: Pingvin Share X 0.19.0 before 1.22.0 Account Takeover via OAuth Email Linking

Published Oct 9, 2026
·
Updated

Pingvin Share X from 0.19.0 before 1.22.0 contains an improper authentication vulnerability that allows remote unauthenticated attackers to take over accounts by abusing automatic OAuth email linking in OAuthService.signUp(). Attackers can register a victim's unverified email on an enabled OAuth/OIDC provider, exploiting the missing emailverified check in GenericOidcProvider, to sign in as the victim including administrators while bypassing TOTP.

Affected Software

1 affected component
Pingvin Share Pingvin Share X>=0.19.0<1.22.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Pingvin Share X to a version that resolves this vulnerability.

    Fixed in 1.22.0

Event History

Oct 9, 2026
CVE Published
via MITRE·04:04 PM
Data Sourced
via MITRE·04:04 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to account takeover?

Pingvin Share X versions from 0.19.0 up to, but not including, 1.22.0 are affected when an OAuth/OIDC provider is enabled and automatic OAuth email linking is used. Accounts whose email addresses can be registered as unverified at the enabled provider, including administrator accounts, may be exposed.

2

What does an attacker need to exploit this issue?

The attacker needs network access to the affected instance and does not need an existing Pingvin Share account, privileges, or user interaction. They must be able to register the target account's email address as unverified with an enabled OAuth/OIDC provider.

3

Does TOTP prevent exploitation?

No. The described OAuth sign-in path can allow an attacker to sign in as the victim while bypassing TOTP.

4

What should be prioritized for remediation?

Upgrade Pingvin Share X to version 1.22.0 or later. The fix addresses the missing email_verified validation in GenericOidcProvider that enables automatic email-linking abuse.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203