Sceawere
Vulnerability Detail
CVE-2026-105692UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Penpot Improper Authorization Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.4
- Creation Date
- 1h ago
- Vendor
- penpot
- Product
- penpot
- Attack Type
- CWE-284: Improper Access Control
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-share-link RPC retrieves a caller-selected share-link ID and verifies only that the caller can edit the parent file. It does not verify that the caller created the share link or has owner or administrator authority, allowing any file editor who knows a share-link UUID to delete links created by other users and revoke external reviewers' access. This issue is fixed in version 2.18.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.4",
"pubDate": "2026-10-05T20:17:19.420Z",
"pubdate": "2026-10-05T20:17:19.420Z",
"executiveSummary": "The Penpot design and prototyping platform, prior to version 2.18.0, is affected by an authorization bypass vulnerability within the delete-share-link RPC function. This flaw allows an authenticated user with edit-level permissions on a specific file to illicitly delete share links created by other users, including those with owner or administrative privileges.\nThe vulnerability stems from an insufficient verification process that fails to validate ownership or administrative authority before executing the deletion command. An attacker only requires the share-link UUID to target specific external review sessions for termination.\nThe primary impact is the unauthorized revocation of access for external reviewers, which disrupts collaboration workflows and exposes the platform to targeted service degradation. By exploiting this authorization gap, malicious actors can systematically remove sharing mechanisms established by project leads or account owners. The attack requires authenticated access to the application, specifically the ability to edit a parent file, which is a common privilege level for project contributors. The vulnerability was remediated in version 2.18.0 through the implementation of proper authorization checks on the RPC execution path.",
"technicalDetails": "The vulnerability is situated within the server-side RPC handler responsible for managing share-link lifecycle operations, specifically identified as the delete-share-link function. The root cause of this security defect is an insecure implementation of the authorization logic where the application enforces an incomplete permission check.\nDuring the execution flow of delete-share-link, the application accepts a caller-provided share-link UUID and proceeds to verify only whether the caller possesses 'edit' permissions for the parent file associated with that link. Critically, the server fails to cross-reference the identity of the user attempting the deletion against the identity of the user who originally generated the share link, nor does it verify if the caller holds the mandatory 'owner' or 'administrator' role required for such administrative modifications.\nAn attacker can exploit this flaw by performing the following steps: First, the attacker must have valid authenticated access to Penpot with at least editor-level permissions on the target file. Second, the attacker must acquire the UUID of a share link they did not create. Given that share-link UUIDs are often predictable or discoverable through captured network traffic or shared documentation, this is a low-barrier requirement. Third, the attacker initiates the delete-share-link RPC call with the target UUID as the payload. Because the server-side logic only validates that the user is an editor of the parent file, the request is processed successfully, leading to the immediate removal of the share link from the database.\nThis leads to a post-exploitation state where the link is permanently destroyed, effectively revoking access for all external stakeholders and reviewers associated with that specific URI. The vulnerability is strictly an authorization issue; the underlying protocol and transport mechanisms function as designed, but the application logic fails to adhere to the principle of least privilege, allowing unauthorized users to perform destructive operations on objects they do not own."
}