Team Profile Management Flaw in Penpot by Penpot
CVE-2026-105687
4.9MEDIUM
What is CVE-2026-105687?
Penpot is an open-source design and prototyping platform that faced a critical access control issue prior to version 2.18.0. This vulnerability allows a non-owner team administrator to delete the owner's membership, effectively locking the owner out of their team and project assets. The flaw undermines the integrity of team management by providing excessive permissions to team admins, which could lead to unauthorized removal of critical team members. This issue has been addressed in version 2.18.0.
Affected Version(s)
penpot < 2.18.0
