CVE-2026-44196

Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows an attacker who has obtained a valid username and password to skip the second-factor authentication (TOTP) requirement entirely. Although, an attacker still needs the user's password to reach this stage. This vulnerability is fixed in 1.16.3.
Configurations

No configuration.

History

12 May 2026, 18:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-12 18:17

Updated : 2026-05-13 18:21


NVD link : CVE-2026-44196

Mitre link : CVE-2026-44196

CVE.ORG link : CVE-2026-44196


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication

CWE-697

Incorrect Comparison