Penpot · Penpot · CVE-2026-105688
**Name of the Vulnerable Software and Affected Versions**
Penpot versions prior to 2.18.0
**Description**
In the create-team-invitations and invitation acceptance paths, a non-owner team administrator can assign the owner role to another account. This occurs because invitation roles are persisted and applied without the role-ceiling check used by the `update-team-member-role()` function. An administrator can exploit this to create multiple owners and subsequently gain owner-only control over the team.
**Recommendations**
Update to version 2.18.0.