PT-2026-83954 · Pangolin · Pangolin

·

CVE-2026-72001

·

Published

2026-08-31

·

Updated

2026-08-31

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Pangolin versions prior to 1.22.0
Description An authentication bypass exists that allows unauthenticated attackers to access protected resources. By providing an attacker-controlled URL parameter to the share-link authentication endpoint, the expected resource identifier is omitted from the token verification call. An attacker with a single valid share link for any resource can authenticate against arbitrary resources across different organizations, bypassing SSO, resource passwords, PIN codes, email allowlists, and header authentication.
Recommendations Update Pangolin to version 1.22.0 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72001

Affected Products

Pangolin