PT-2026-106209 · Penpot · Penpot
CVSS v3.1
6.7
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Penpot versions prior to 2.18.0
Description
In the create-team-invitations and invitation acceptance paths, a non-owner team administrator can assign the owner role to another account. This occurs because invitation roles are persisted and applied without the role-ceiling check used by the
update-team-member-role() function. An administrator can exploit this to create multiple owners and subsequently gain owner-only control over the team.Recommendations
Update to version 2.18.0.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Penpot