Penpot · Penpot · CVE-2026-105692
**Name of the Vulnerable Software and Affected Versions**
Penpot versions prior to 2.18.0
**Description**
An issue exists in the `delete-share-link` RPC where the system verifies only if the caller has permission to edit the parent file, failing to confirm if the caller created the share link or possesses owner or administrator authority. This allows any user with file editor permissions who knows a share-link UUID to delete links created by other users, effectively revoking access for external reviewers.
**Recommendations**
Update to version 2.18.0.