Team Profile Management Flaw in Penpot by Penpot
CVE-2026-105687

4.9MEDIUM

Key Information:

Vendor

Penpot

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105687?

Penpot is an open-source design and prototyping platform that faced a critical access control issue prior to version 2.18.0. This vulnerability allows a non-owner team administrator to delete the owner's membership, effectively locking the owner out of their team and project assets. The flaw undermines the integrity of team management by providing excessive permissions to team admins, which could lead to unauthorized removal of critical team members. This issue has been addressed in version 2.18.0.

Affected Version(s)

penpot < 2.18.0

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.