PT-2026-40332 · Unknown · Pingvin Share

CVE-2026-44196

·

Published

2026-05-12

·

Updated

2026-05-12

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Pingvin Share X versions 1.14.1 through 1.16.2
Description An authentication bypass allows an attacker with a valid username and password to skip the second-factor authentication (TOTP) requirement. Time-based One-Time Password (TOTP) is a temporary code generated by an app to provide an extra layer of security.
Recommendations Update to version 1.16.3.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44196
GHSA-J679-VP39-QWQQ

Affected Products

Pingvin Share