{"id":"CVE-2026-108157","title":"Pingvin Share X from 0.19.0 before 1.22.0 contains an improper authentication vulnerability that allows remote unauthenticated attackers to take over accounts by abusing automatic OAuth email linking in OAuthService.signUp()","summary":"Pingvin Share X from 0.19.0 before 1.22.0 contains an improper authentication vulnerability that allows remote unauthenticated attackers to take over accounts by abusing automatic OAuth email linking in OAuthService.signUp(). Attackers c…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-287"],"published":"2026-10-09","updated":"2026-10-09","sourceUpdated":"2026-10-09T18:17:07.240","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-108157","references":[{"url":"https://github.com/smp46/pingvin-share-x","label":"disclosure@vulncheck.com"},{"url":"https://github.com/smp46/pingvin-share-x/blob/de7ffecf9bfc4976993149a5c4c98efe35161424/backend/src/oauth/oauth.service.ts#L158-L175","label":"disclosure@vulncheck.com"},{"url":"https://github.com/smp46/pingvin-share-x/commit/07aa8c0a96030c439e9018ce94a2778bd37304e6","label":"disclosure@vulncheck.com"},{"url":"https://github.com/smp46/pingvin-share-x/releases/tag/v1.22.0","label":"disclosure@vulncheck.com"},{"url":"https://github.com/smp46/pingvin-share-x/security/advisories/GHSA-wrcg-4874-45p7","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/pingvin-share-x-0.19.0-before-1.22.0-account-takeover-via-oauth-email-linking","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"ingestedAt":"2026-10-09T18:07:39.417Z","slug":"CVE-2026-108157","body":"## Overview\n\nPingvin Share X from 0.19.0 before 1.22.0 contains an improper authentication vulnerability that allows remote unauthenticated attackers to take over accounts by abusing automatic OAuth email linking in OAuthService.signUp(). Attackers can register a victim's unverified email on an enabled OAuth/OIDC provider, exploiting the missing email_verified check in GenericOidcProvider, to sign in as the victim including administrators while bypassing TOTP.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}