
One Pangolin share link opens every other org’s resource. Working PoC dropped Sept 24!! CVE-2026-72001: "POST /api/v1/auth/resource/{id}/access-token" does not bind the presented "accessTokenId" to the URL resource id. Steal or issue one share link, mint a session for a different resource, then hit Badger "/exchange-session" → "/verify-session" the same way Traefik does. Bypasses SSO, resource passwords, PINs, email allowlists. Lab boots "fosrl/pangolin:1.21.1". Fixed in ≥1.22.0. https://www.vulncheck.com/advisories/pangolin-authentication-bypass-via-share-link-endpoint #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #AppSec #AuthBypass
