Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows an attacker who has obtained a valid username and password to skip the second-factor authentication (TOTP) requirement entirely. Although, an attacker still needs the user's password to reach this stage. This vulnerability is fixed in 1.16.3.
The vulnerability consists of incorrect comparison or lack of enforcement of second-factor authentication verification (CWE-287, CWE-697) after correct password submission. Although the attacker must first obtain valid login credentials (username and password), the TOTP mechanism can be completely bypassed by proceeding directly to an authenticated session without providing a one-time code.
An attacker who possesses stolen or compromised user credentials can gain full access to the user's account by bypassing two-factor authentication — resulting in a breach of confidentiality and integrity of stored data and files.
Pingvin Share X should be updated to version 1.16.3, where the vulnerability has been fixed. As an interim workaround, consider disabling exposure of the instance to the public network until the patch is implemented.
Pingvin Share X versions 1.14.1 to 1.16.2 (inclusive)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N