PT-2026-106209 · Penpot · Penpot

·

CVE-2026-105688

·

Published

2026-10-05

·

Updated

2026-10-06

CVSS v3.1

6.7

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions Penpot versions prior to 2.18.0
Description In the create-team-invitations and invitation acceptance paths, a non-owner team administrator can assign the owner role to another account. This occurs because invitation roles are persisted and applied without the role-ceiling check used by the update-team-member-role() function. An administrator can exploit this to create multiple owners and subsequently gain owner-only control over the team.
Recommendations Update to version 2.18.0.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105688

Affected Products

Penpot