CVE-2026-105693
Deferred Deferred - Pending Action

Unauthenticated Access to Sensitive Share Data in Penpot

Vulnerability report for CVE-2026-105693, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the unauthenticated get-view-only-bundle RPC returns every share-link row for a file even when the caller authenticated with only one scoped share link. A holder of a restrictive link can obtain other links' secret IDs, page scopes, comment permissions, and inspection permissions, then replay a more permissive token to access page data that was not included in the original share. This issue is fixed in version 2.18.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
penpot penpot < 2.18.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105693 is a vulnerability in Penpot, an open-source design platform. It involves an unauthenticated RPC method called get-view-only-bundle that returns all share-link tokens for a file, even when the user only has access to a restrictive share link. This allows an attacker to obtain other users' share-link secrets, page scopes, and permissions, potentially escalating their access to view unauthorized content.

Detection Guidance

To detect this vulnerability, check if your Penpot instance is running a version prior to 2.18.0. Inspect network traffic for unauthenticated RPC calls to the get-view-only-bundle endpoint. Look for responses containing multiple share-link tokens when only one token was used in the request.

Impact Analysis

If you use Penpot with shared files, an attacker could exploit this to access files or pages they shouldn't see by stealing share-link tokens. Even with a restricted link, they could discover and use more permissive tokens to view sensitive design data, components, or code. This could lead to data leaks or unauthorized access to proprietary information.

Compliance Impact

This vulnerability could violate compliance requirements like GDPR (data protection) or HIPAA (health information privacy) by allowing unauthorized access to sensitive files. If design files contain personal or confidential data, the exposure could result in regulatory penalties, loss of trust, or legal consequences due to insufficient access controls.

Mitigation Strategies

Upgrade Penpot to version 2.18.0 or later immediately. If upgrading is not possible, restrict network access to the get-view-only-bundle RPC endpoint until patched. Review all share-link tokens for sensitive files and revoke any potentially exposed tokens.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105693. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart