Authorization Flaw in Penpot Design Platform
CVE-2026-105692

5.4MEDIUM

Key Information:

Vendor

Penpot

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105692?

The Penpot design and prototyping platform features a vulnerability that enables any file editor to delete share links created by other users. This flaw arises because the delete-share-link RPC does not verify whether the requester is the creator of the share link or possesses the necessary owner or administrator rights. As a result, external reviewers' access can be revoked unknowingly by users familiar with the share-link UUID. The issue has been addressed in version 2.18.0 with enhanced verification checks.

Affected Version(s)

penpot < 2.18.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.