CVE-CVE-2026-72001
Severity
HIGH
CVSS Score
8.1
Description
Pangolin before 1.22.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access any protected resource by supplying an attacker-controlled URL parameter to the share-link authentication endpoint that omits the expected resource identifier from the token verification call. Attackers holding a single valid share link for any resource can authenticate against arbitrary resources across different organizations, bypassing all configured authentication methods in...
PoCs for CVE-CVE-2026-72001
CVE-2026-72001-Pangolin-Cross-Org-Auth-Bypass
RCE
Python
0
BiiTts
2026-09-24