Sceawere

Vulnerability Detail

CVE-2026-105688UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Penpot Improper Privilege Assignment Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.7
Creation Date
1h ago
Vendor
penpot
Product
penpot
Attack Type
CWE-269: Improper Privilege Management
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, create-team-invitations and the invitation acceptance path allow a non-owner team administrator to assign the owner role because invitation roles are persisted and applied without the role-ceiling check used by update-team-member-role. An administrator can invite another account as an owner, create multiple owners, and then use the new owner account to obtain owner-only control over the team. This issue is fixed in version 2.18.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.7",
  "pubDate": "2026-10-05T20:17:18.193Z",
  "pubdate": "2026-10-05T20:17:18.193Z",
  "executiveSummary": "A privilege escalation vulnerability exists in Penpot versions prior to 2.18.0, stemming from insufficient validation of team invitation roles. The flaw allows a non-owner team administrator to improperly assign the 'owner' role to new or existing members during the invitation process.\nThis vulnerability bypasses the intended 'role-ceiling' security check typically enforced by the update-team-member-role function. By exploiting this oversight, an attacker with administrative privileges can elevate their own account or secondary accounts to the team owner level, effectively gaining full administrative control over the team environment.\nThe vulnerability represents a significant security risk, as it permits unauthorized privilege escalation, circumventing established administrative boundaries. Exploitation requires authenticated access as a team administrator, but does not necessitate interaction from the original team owner. Successful exploitation results in complete compromise of team-level assets and management capabilities. Organizations are urged to upgrade to version 2.18.0 or later to remediate the flaw.",
  "technicalDetails": "The root cause of this vulnerability lies in an inconsistent implementation of authorization logic between the invitation workflow and the member update workflow in Penpot. While the update-team-member-role function correctly enforces a role-ceiling check to prevent unauthorized privilege escalation by non-owner administrators, the create-team-invitations and the associated invitation acceptance path fail to perform an identical validation.\nIn the affected versions, the application persists the role defined in the invitation object without verifying whether the assigning user has the authority to delegate the 'owner' role. Because the validation logic is bypassed during the invitation lifecycle, an administrator can arbitrarily assign the owner role to any invitee. This discrepancy allows the administrator to inject an owner role into the database for a target account.\nThe attack flow proceeds as follows: First, an authenticated attacker with 'administrator' privileges (but not 'owner' privileges) initiates a team invitation process. Second, the attacker manipulates the request to specify the role as 'owner' for the invited account. Third, the backend accepts the invitation role without verifying the initiator's authority to grant that specific privilege. Fourth, upon the acceptance of the invitation, the system applies the owner role to the invitee. If the attacker invites a secondary account they control, they can subsequently authenticate as that account to assume full ownership control over the team, effectively bypassing the role hierarchy.\nThis vulnerability effectively subverts the role-based access control (RBAC) model of the application. The persistent nature of the invitation role ensures that the unauthorized elevation remains active post-acceptance, granting the attacker perpetual access to owner-only features. Because the application logic relies on the invitation record for privilege assignment at the point of acceptance rather than a server-side permission check, the vulnerability is highly reliable and does not require complex bypass techniques. The issue is resolved in version 2.18.0, where the role-ceiling validation logic has been unified across all member management and invitation endpoints, ensuring that only existing owners can promote other users to the owner role."
}
CVE-2026-105688: Penpot Improper Privilege Assignment Vulnerability (MEDIUM Severity, CVSS: 6.7) | Sceawere