CVE-2026-44196
Gravedad CVSS v3.1:
CRÍTICA
Tipo:
CWE-287
Autenticación incorrecta
Fecha de publicación:
12/05/2026
Última modificación:
13/05/2026
Descripción
*** Pendiente de traducción *** Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows an attacker who has obtained a valid username and password to skip the second-factor authentication (TOTP) requirement entirely. Although, an attacker still needs the user's password to reach this stage. This vulnerability is fixed in 1.16.3.
Impacto
Puntuación base 3.x
9.10
Gravedad 3.x
CRÍTICA



