CVE-2026-108157: SMP46 Pingvin-Share-X
High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.
Pingvin Share X from 0.19.0 before 1.22.0 contains an improper authentication vulnerability that allows remote unauthenticated attackers to take over accounts by abusing automatic OAuth email linking in OAuthService.signUp(). Attackers can register a victim's unverified email on an enabled OAuth/OIDC provider, exploiting the missing email_verified check in GenericOidcProvider, to sign in as the victim including administrators while bypassing TOTP.
Affected products
- SMP46 Pingvin-Share-X: from 0.19.0, before 1.22.0 (fixed in 1.22.0)
Published 2026-10-09. Last modified 2026-10-09.