Sceawere
Vulnerability Detail
CVE-2026-105687UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Penpot Improper Authorization Deletion Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.9
- Creation Date
- 2h ago
- Vendor
- penpot
- Product
- penpot
- Attack Type
- CWE-269: Improper Privilege Management
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-team-member RPC allows a team administrator to remove any member other than themselves but does not protect the team owner. A non-owner administrator can delete the owner's team-profile-rel membership and lock the owner out of the team and its projects, files, fonts, and media. This issue is fixed in version 2.18.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.9",
"pubDate": "2026-10-05T20:17:17.997Z",
"pubdate": "2026-10-05T20:17:17.997Z",
"executiveSummary": "A critical improper authorization vulnerability exists in the Penpot design and prototyping platform, specifically within the delete-team-member RPC function.\nThe vulnerability allows an authenticated user with administrative privileges on a team to delete the membership of the team owner, effectively revoking the owner's access to all team-associated assets.\nThis flaw stems from a lack of server-side validation regarding the hierarchical relationship between a team administrator and the team owner during the member removal process.\nThe impact is significant, as an attacker with administrative access can perform an account lockout against the team owner, leading to a loss of control over projects, files, fonts, and media.\nThis vulnerability affects Penpot versions prior to 2.18.0 and requires the attacker to hold an existing administrator role within the target team to execute the exploit.\nThe vulnerability represents a failure in access control logic where administrative rights are not properly scoped to prevent the destruction of higher-privileged account memberships.",
"technicalDetails": "The vulnerability resides within the RPC-based implementation of member management, specifically the delete-team-member function. The application logic fails to implement a robust authorization check that verifies whether the account being removed holds the 'owner' role within the context of the team-profile-rel entity.\nIn Penpot's permission model, a 'team administrator' role is granted sufficient authority to invoke the delete-team-member RPC; however, the backend logic incorrectly treats all administrative users as peers regardless of their specific role designation (e.g., admin vs. owner).\nThe attack flow proceeds as follows: 1) An authenticated user possessing the administrator role within a specific team identifies the team owner's unique membership identifier via enumeration of the team-profile-rel associations. 2) The attacker issues a request to the delete-team-member RPC, targeting the team owner's association record. 3) The server-side controller processes the RPC call without validating the hierarchical integrity of the requester, resulting in the successful deletion of the owner's record from the team's membership database.\nThe post-exploitation impact is a forced lockout. Once the team-profile-rel record for the owner is removed, the system no longer associates the owner's identity with the team resources, including projects, design files, fonts, and media assets. This effectively orphans the team, potentially resulting in a complete loss of ownership and administrative control for the primary owner.\nThis vulnerability is restricted to users who have already achieved administrative-level access within a specific team, meaning it is not accessible to standard members or unauthenticated users. The attack is performed via standard application-level protocols handled by the platform's backend RPC framework.\nThe root cause is a failure in access control enforcement where the application layer lacks a mandatory check to prevent users from modifying or deleting accounts that possess higher-privilege attributes, such as ownership, within a structured authorization hierarchy."
}