PT-2026-106208 · Penpot · Penpot
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Penpot versions prior to 2.18.0
Description
An issue exists in the
delete-team-member RPC where a team administrator can remove any member except themselves, but the system fails to protect the team owner. This allows a non-owner administrator to delete the owner's team-profile-rel membership, effectively locking the owner out of the team and all associated projects, files, fonts, and media.Recommendations
Update to version 2.18.0.
Fix
Improper Privilege Management
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Penpot