Impact
Pangolin before version 1.22.0 contains a flaw that allows an attacker who can control a URL parameter to bypass authentication when using the share‑link endpoint. The vulnerability lies in the omission of the expected resource identifier during token verification, giving the attacker unauthorized access to protected content. The high CVSS score of 8.6 reflects the significant potential for compromising confidentiality and integrity across all organizations that use Pangolin.
Affected Systems
Any installation of Pangolin running a version older than 1.22.0 is affected. The vulnerability affects all resources that are exposed via the share‑link feature, regardless of the organization they belong to.
Risk and Exploitability
Because the flaw enables authentication bypass without any prerequisite other than a valid share link, the risk is high. Attackers can obtain a single share link and then use the share‑link endpoint to access arbitrary resources, bypassing SSO, passwords, PINs, allowlists, and header authentication. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the severity is clearly high. The likely attack vector is the share‑link endpoint and can be executed by an unauthenticated attacker with a share link string.
OpenCVE Enrichment