Role Escalation Vulnerability in Penpot Design Platform
CVE-2026-105688
6.7MEDIUM
What is CVE-2026-105688?
Penpot, an open-source design and prototyping platform, has a vulnerability where a non-owner team administrator can improperly assign the owner role to another user. This occurs due to the lack of role-validation checks during the invitation process for team management. An administrator can invite a new account as an owner or create multiple owners, potentially leading to unauthorized control over the team. This issue is addressed in version 2.18.0.
Affected Version(s)
penpot < 2.18.0
