CVE-2026-105688
Deferred Deferred - Pending Action

Privilege Escalation in Penpot via Owner Role Assignment

Vulnerability report for CVE-2026-105688, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, create-team-invitations and the invitation acceptance path allow a non-owner team administrator to assign the owner role because invitation roles are persisted and applied without the role-ceiling check used by update-team-member-role. An administrator can invite another account as an owner, create multiple owners, and then use the new owner account to obtain owner-only control over the team. This issue is fixed in version 2.18.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
penpot penpot < 2.18.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Penpot allows a team administrator (not the owner) to escalate their privileges to owner by inviting another user with the owner role through the team invitation system. The issue occurs because the invitation path lacks the same ownership guard present in the direct role-change path. When the invitation is accepted, the new user becomes a team owner, allowing them to then promote the original admin to owner.

Detection Guidance

This vulnerability is specific to Penpot's team invitation system and requires checking the Penpot application logs and team member roles. Look for logs indicating non-owner admins assigning the owner role via invitations. Commands may include checking Penpot server logs for unusual invitation activity or verifying team member roles through Penpot's admin interface.

Impact Analysis

An attacker with admin privileges on a team could exploit this to gain owner-level control. This could allow them to manage team settings, access sensitive data, or perform actions restricted to owners. The vulnerability requires the attacker to already have admin access, limiting the initial attack surface.

Compliance Impact

This vulnerability could lead to unauthorized privilege escalation, potentially violating access control requirements in GDPR and HIPAA. Unauthorized owner access may result in data breaches or improper data handling, which could lead to non-compliance with these regulations.

Mitigation Strategies

Upgrade Penpot to version 2.18.0 or later to apply the fix. Review team member roles to identify unauthorized owner assignments and remove any extra owners created through this vulnerability. Ensure no non-owner admins have granted the owner role.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105688. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart