CVE-2026-105687
Deferred Deferred - Pending Action

Privilege Escalation in Penpot via Team Owner Deletion

Vulnerability report for CVE-2026-105687, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-team-member RPC allows a team administrator to remove any member other than themselves but does not protect the team owner. A non-owner administrator can delete the owner's team-profile-rel membership and lock the owner out of the team and its projects, files, fonts, and media. This issue is fixed in version 2.18.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
penpot penpot < 2.18.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Penpot allows a team administrator who is not the team owner to remove the owner from the team using the delete-team-member RPC command. This locks the owner out of their own team and all associated resources like projects, files, fonts, and media. The issue occurs because the command does not check if the target member is the team owner before deletion.

Detection Guidance

This vulnerability is specific to Penpot's team management system and cannot be detected via standard network or system commands. Instead, check if your Penpot instance is running a version prior to 2.18.0. Use the admin dashboard or API to verify the installed version and compare it against the fixed release.

Impact Analysis

If you are a team owner in Penpot, an attacker with admin privileges could remove you from your team, preventing you from accessing your projects and resources. Even if you are an admin, you could accidentally lock out the team owner. The only way to regain access is to be re-invited by another remaining admin.

Compliance Impact

This vulnerability could lead to unauthorized access removal, potentially violating data integrity and availability requirements in GDPR and HIPAA. If a team owner is locked out, critical design or project data may become inaccessible, impacting compliance with access control and audit logging requirements.

Mitigation Strategies

Upgrade Penpot to version 2.18.0 or later immediately. Ensure all team administrators are aware of the risk and avoid granting unnecessary admin privileges. Monitor team membership changes for suspicious activity, such as the removal of the team owner.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105687. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart