CVE-2026-108163: SMP46 Pingvin-Share-X
Medium severity, CVSS 6.5.
Pingvin Share X before 1.22.0 contains an ineffective rate limiting vulnerability because throttler TTL values specified in seconds are interpreted as milliseconds. Unauthenticated attackers can send effectively unthrottled requests to /api/auth/signIn, /api/auth/signIn/totp and /api/auth/resetPassword to brute-force passwords and TOTP codes.
Affected products
- SMP46 Pingvin-Share-X: before 1.22.0 (fixed in 1.22.0)
Published 2026-10-10. Last modified 2026-10-10.