PT-2026-83954 · Pangolin · Pangolin
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Pangolin versions prior to 1.22.0
Description
An authentication bypass exists that allows unauthenticated attackers to access protected resources. By providing an attacker-controlled URL parameter to the share-link authentication endpoint, the expected resource identifier is omitted from the token verification call. An attacker with a single valid share link for any resource can authenticate against arbitrary resources across different organizations, bypassing SSO, resource passwords, PIN codes, email allowlists, and header authentication.
Recommendations
Update Pangolin to version 1.22.0 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pangolin