PT-2026-40332 · Unknown · Pingvin Share
Published
2026-05-12
·
Updated
2026-05-12
·
CVE-2026-44196
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Pingvin Share X versions 1.14.1 through 1.16.2
Description
An authentication bypass allows an attacker with a valid username and password to skip the second-factor authentication (TOTP) requirement. Time-based One-Time Password (TOTP) is a temporary code generated by an app to provide an extra layer of security.
Recommendations
Update to version 1.16.3.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pingvin Share