CVE-2026-108157: Pingvin Share X 0.19.0 before 1.22.0 Account Takeover via OAuth Email Linking
Pingvin Share X from 0.19.0 before 1.22.0 contains an improper authentication vulnerability that allows remote unauthenticated attackers to take over accounts by abusing automatic OAuth email linking in OAuthService.signUp(). Attackers can register a victim's unverified email on an enabled OAuth/OIDC provider, exploiting the missing emailverified check in GenericOidcProvider, to sign in as the victim including administrators while bypassing TOTP.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Pingvin Share Xto a version that resolves this vulnerability.Fixed in 1.22.0
Event History
Frequently Asked Questions
Which deployments are exposed to account takeover?
Pingvin Share X versions from 0.19.0 up to, but not including, 1.22.0 are affected when an OAuth/OIDC provider is enabled and automatic OAuth email linking is used. Accounts whose email addresses can be registered as unverified at the enabled provider, including administrator accounts, may be exposed.
What does an attacker need to exploit this issue?
The attacker needs network access to the affected instance and does not need an existing Pingvin Share account, privileges, or user interaction. They must be able to register the target account's email address as unverified with an enabled OAuth/OIDC provider.
Does TOTP prevent exploitation?
No. The described OAuth sign-in path can allow an attacker to sign in as the victim while bypassing TOTP.
What should be prioritized for remediation?
Upgrade Pingvin Share X to version 1.22.0 or later. The fix addresses the missing email_verified validation in GenericOidcProvider that enables automatic email-linking abuse.