Pangolin versions before 1.22.0 contain a critical authentication bypass vulnerability tracked as CVE-2026-72001. The flaw resides in the share-link authentication endpoint, where an attacker-controlled URL parameter can omit the expected resource identifier from the token verification call. An attacker possessing a single valid share link for any resource can leverage this to authenticate against arbitrary resources across different organizations. The vulnerability effectively bypasses all configured authentication mechanisms, including SSO, resource passwords, PIN codes, email allowlists, and header authentication. The attack requires no prior authentication, making it accessible to unauthenticated threat actors. The issue has been patched in Pangolin version 1.22.0. Organizations using affected versions should upgrade immediately to mitigate unauthorized access risks.