Executive brief
Pingvin Share X is a self-hosted file sharing platform used to manage and distribute large files. A security flaw allows attackers who have stolen a user's password to completely bypass the required second-factor authentication (TOTP). This could lead to unauthorized access to sensitive files, data theft, and full account takeover.
Technical details
An authentication bypass vulnerability exists in Pingvin Share X due to improper authentication (CWE-287) and incorrect comparison logic (CWE-697) during the login flow. While the platform requires a password, it fails to properly enforce the Time-based One-Time Password (TOTP) second-factor requirement. A remote attacker with valid primary credentials can bypass the 2FA stage to gain full access to the account. This allows for unauthorized management of shares and access to stored data, including S3-backed storage. The issue is resolved in version 1.16.3.
Affected products
- smp46 Pingvin Share X 1.14.1 - 1.16.2
Timeline
- 2026-04-27: advisory: Original GitHub advisory published
- 2026-05-12: disclosed: NVD publication date