CVE-2026-105692
Deferred Deferred - Pending Action

Insecure Share Link Deletion in Penpot

Vulnerability report for CVE-2026-105692, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-share-link RPC retrieves a caller-selected share-link ID and verifies only that the caller can edit the parent file. It does not verify that the caller created the share link or has owner or administrator authority, allowing any file editor who knows a share-link UUID to delete links created by other users and revoke external reviewers' access. This issue is fixed in version 2.18.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
penpot penpot < 2.18.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105692 is an Insecure Direct Object Reference (IDOR) vulnerability in the Penpot design platform. It allows any user with file editing permissions to delete shared links they did not create. The vulnerability existed because the delete-share-link RPC command only checked if the caller could edit the file but did not verify if they owned the specific share link.

Detection Guidance

To detect this vulnerability, check if your Penpot instance is running a version prior to 2.18.0. Use commands like 'curl -s https://your-penpot-instance.com/api/version' or inspect the Docker image tag if self-hosted. Look for unauthorized deletion of share links by reviewing audit logs for delete-share-link RPC calls.

Impact Analysis

This vulnerability could disrupt collaborative workflows by allowing unauthorized users to delete share links created by others. It may revoke access for external reviewers without their consent, potentially causing data access issues or workflow interruptions.

Compliance Impact

This vulnerability could indirectly impact compliance with GDPR and HIPAA by enabling unauthorized access revocation. Under GDPR, unauthorized deletion of shared links may disrupt data access controls, potentially violating principles of data integrity and availability. For HIPAA, if shared links grant access to protected health information, unauthorized deletion could interfere with required access controls for PHI.

Mitigation Strategies

Upgrade Penpot to version 2.18.0 or later immediately. If upgrading is not possible, restrict file edit permissions to trusted users only. Review and remove any unauthorized share links created by other users. Monitor for unusual deletion activity in audit logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105692. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart