Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Andersthemagi

#43933of 57,577
6.7Total CVSS
Vulnerabilities · 1
PT-2026-106209
6.7
2026-10-05
Penpot · Penpot · CVE-2026-105688
**Name of the Vulnerable Software and Affected Versions** Penpot versions prior to 2.18.0 **Description** In the create-team-invitations and invitation acceptance paths, a non-owner team administrator can assign the owner role to another account. This occurs because invitation roles are persisted and applied without the role-ceiling check used by the `update-team-member-role()` function. An administrator can exploit this to create multiple owners and subsequently gain owner-only control over the team. **Recommendations** Update to version 2.18.0.