Sceawere

Vulnerability Detail

CVE-2026-105684UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Penpot Broken Access Control Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
1h ago
Vendor
penpot
Product
penpot
Attack Type
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the get-comment-threads, get-comment-thread, and get-comments RPC commands use check-comment-permissions! but do not apply the share link's pages restriction. A holder of a page-scoped share link can retrieve comment threads and full comment bodies from other pages in the same file, including commenter names, email addresses, photos, and page identifiers. The disclosed page identifiers can also be used with affected page-reading functionality to access unshared design content. This issue is fixed in version 2.18.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-05T20:17:17.343Z",
  "pubdate": "2026-10-05T20:17:17.343Z",
  "executiveSummary": "A broken access control vulnerability exists in Penpot prior to version 2.18.0, stemming from improper authorization checks within specific RPC commands. The flaw permits users possessing restricted, page-scoped share links to bypass intended boundary limitations. Consequently, an unauthorized actor can gain access to sensitive information, including full comment threads, user metadata such as email addresses and photos, and unauthorized design content identifiers. This represents a significant exposure of private project data, enabling attackers to view information from pages they were not granted access to within the same file. The vulnerability affects the confidentiality and integrity of design assets, as disclosed page identifiers can be leveraged to interact with other unauthorized functionality, further broadening the scope of the data breach. The issue requires no escalated privileges beyond the possession of a valid, yet restricted, share link, making the exploitation vector accessible to any user with legitimate but limited access to the environment.",
  "technicalDetails": "The root cause of this vulnerability lies in an insufficient implementation of authorization logic within the RPC command processing architecture. Specifically, the RPC functions 'get-comment-threads', 'get-comment-thread', and 'get-comments' rely on the 'check-comment-permissions!' function, which fails to adequately validate or enforce the constraints associated with page-scoped share links. While these commands correctly identify if a user has baseline access to comment-related functions, they ignore the granular scoping required to restrict access to a specific page identifier.\nThe exploitation flow begins when an attacker, already in possession of a page-scoped share link, targets the affected RPC endpoints. By invoking these commands, the attacker bypasses the internal scoping mechanism that should otherwise restrict requests to the specific page assigned to the link. Because the 'check-comment-permissions!' function does not integrate the share link's page-level restriction, the application server returns the requested comment data—including metadata such as full comment bodies, commenter names, email addresses, and profile photographs—for all pages residing within the same parent design file, regardless of the attacker's actual authorization level for those specific pages.\nFurthermore, the disclosure of these unintended page identifiers serves as a secondary exploitation vector. The system returns the identifiers for pages that were intended to remain private. An attacker can harvest these page identifiers and feed them into other affected page-reading RPC functions, which trust the provided identifiers without cross-referencing them against the user's initial scope of authorization. This allows the attacker to traverse the design file, accessing unauthorized design content that is otherwise hidden from the limited user profile. The vulnerability effectively turns a restricted, page-scoped access token into a file-wide information disclosure mechanism. The exploitation requires the attacker to have at least one valid, restricted link to a file within the system, but does not require administrative access, complex social engineering, or knowledge of system-level credentials. This flaw is fully remediated in Penpot 2.18.0, where the RPC command logic was updated to strictly enforce the page-scoped restriction in conjunction with the existing comment permission checks."
}
CVE-2026-105684: Penpot Broken Access Control Vulnerability (MEDIUM Severity, CVSS: 4.3) | Sceawere