CVE-2026-105688 (GCVE-0-2026-105688)

Vulnerability from cvelistv5 – Published: 2026-10-05 19:50 – Updated: 2026-10-05 19:50
VLAI
Title
Penpot: Team admin can escalate to owner via team invitation (missing owner-role guard on the invitation path)
Summary
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, create-team-invitations and the invitation acceptance path allow a non-owner team administrator to assign the owner role because invitation roles are persisted and applied without the role-ceiling check used by update-team-member-role. An administrator can invite another account as an owner, create multiple owners, and then use the new owner account to obtain owner-only control over the team. This issue is fixed in version 2.18.0.
CWE
  • CWE-269 - Improper Privilege Management
Impacted products
Vendor Product Version
penpot penpot Affected: < 2.18.0
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "product": "penpot",
          "vendor": "penpot",
          "versions": [
            {
              "status": "affected",
              "version": "\u003c 2.18.0"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "Penpot is an open-source design and prototyping platform. Prior to 2.18.0, create-team-invitations and the invitation acceptance path allow a non-owner team administrator to assign the owner role because invitation roles are persisted and applied without the role-ceiling check used by update-team-member-role. An administrator can invite another account as an owner, create multiple owners, and then use the new owner account to obtain owner-only control over the team. This issue is fixed in version 2.18.0."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.7,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H",
            "version": "3.1"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-269",
              "description": "CWE-269: Improper Privilege Management",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-05T19:50:01.439Z",
        "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "shortName": "GitHub_M"
      },
      "references": [
        {
          "name": "https://github.com/penpot/penpot/security/advisories/GHSA-mx4v-cmxq-644v",
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "https://github.com/penpot/penpot/security/advisories/GHSA-mx4v-cmxq-644v"
        },
        {
          "name": "https://github.com/penpot/penpot/commit/5efd9cc3c5689485322f57b644b83a3bd2e33cee",
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://github.com/penpot/penpot/commit/5efd9cc3c5689485322f57b644b83a3bd2e33cee"
        },
        {
          "name": "https://github.com/penpot/penpot/releases/tag/2.18.0",
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://github.com/penpot/penpot/releases/tag/2.18.0"
        }
      ],
      "source": {
        "advisory": "GHSA-mx4v-cmxq-644v",
        "discovery": "UNKNOWN"
      },
      "title": "Penpot: Team admin can escalate to owner via team invitation (missing owner-role guard on the invitation path)"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
    "assignerShortName": "GitHub_M",
    "cveId": "CVE-2026-105688",
    "datePublished": "2026-10-05T19:50:01.439Z",
    "dateReserved": "2026-10-05T17:48:58.626Z",
    "dateUpdated": "2026-10-05T19:50:01.439Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "nvd": {
      "cve": {
        "affected": [
          {
            "affectedData": [
              {
                "product": "penpot",
                "vendor": "penpot",
                "versions": [
                  {
                    "status": "affected",
                    "version": "\u003c 2.18.0"
                  }
                ]
              }
            ],
            "source": "security-advisories@github.com"
          }
        ],
        "cveTags": [],
        "descriptions": [
          {
            "lang": "en",
            "value": "Penpot is an open-source design and prototyping platform. Prior to 2.18.0, create-team-invitations and the invitation acceptance path allow a non-owner team administrator to assign the owner role because invitation roles are persisted and applied without the role-ceiling check used by update-team-member-role. An administrator can invite another account as an owner, create multiple owners, and then use the new owner account to obtain owner-only control over the team. This issue is fixed in version 2.18.0."
          }
        ],
        "id": "CVE-2026-105688",
        "lastModified": "2026-10-05T20:17:18.347",
        "metrics": {
          "cvssMetricV31": [
            {
              "cvssData": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.7,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H",
                "version": "3.1"
              },
              "exploitabilityScore": 1.2,
              "impactScore": 5.5,
              "source": "security-advisories@github.com",
              "type": "Secondary"
            }
          ]
        },
        "published": "2026-10-05T20:17:18.193",
        "references": [
          {
            "source": "security-advisories@github.com",
            "url": "https://github.com/penpot/penpot/commit/5efd9cc3c5689485322f57b644b83a3bd2e33cee"
          },
          {
            "source": "security-advisories@github.com",
            "url": "https://github.com/penpot/penpot/releases/tag/2.18.0"
          },
          {
            "source": "security-advisories@github.com",
            "url": "https://github.com/penpot/penpot/security/advisories/GHSA-mx4v-cmxq-644v"
          }
        ],
        "sourceIdentifier": "security-advisories@github.com",
        "vulnStatus": "Deferred",
        "weaknesses": [
          {
            "description": [
              {
                "lang": "en",
                "value": "CWE-269"
              }
            ],
            "source": "security-advisories@github.com",
            "type": "Primary"
          }
        ]
      }
    }
  }
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…