๐Ÿ” CVE Alert

CVE-2026-105688

MEDIUM 6.7

Penpot: Team admin can escalate to owner via team invitation (missing owner-role guard on the invitation path)

CVSS Score
6.7
EPSS Score
0.0%
EPSS Percentile
0th

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, create-team-invitations and the invitation acceptance path allow a non-owner team administrator to assign the owner role because invitation roles are persisted and applied without the role-ceiling check used by update-team-member-role. An administrator can invite another account as an owner, create multiple owners, and then use the new owner account to obtain owner-only control over the team. This issue is fixed in version 2.18.0.

CWE CWE-269
Vendor penpot
Product penpot
Published Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for penpot penpot

Be the first to know when new medium vulnerabilities affecting penpot penpot are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
High

Affected Versions

penpot / penpot
< 2.18.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/penpot/penpot/security/advisories/GHSA-mx4v-cmxq-644v github.com: https://github.com/penpot/penpot/commit/5efd9cc3c5689485322f57b644b83a3bd2e33cee github.com: https://github.com/penpot/penpot/releases/tag/2.18.0