Sceawere

Vulnerability Detail

CVE-2026-105693UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Penpot Improper Authorization Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
1h ago
Vendor
penpot
Product
penpot
Attack Type
CWE-862: Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the unauthenticated get-view-only-bundle RPC returns every share-link row for a file even when the caller authenticated with only one scoped share link. A holder of a restrictive link can obtain other links' secret IDs, page scopes, comment permissions, and inspection permissions, then replay a more permissive token to access page data that was not included in the original share. This issue is fixed in version 2.18.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-05T20:17:19.627Z",
  "pubdate": "2026-10-05T20:17:19.627Z",
  "executiveSummary": "An improper authorization vulnerability exists in the Penpot design platform prior to version 2.18.0. The issue resides within the unauthenticated get-view-only-bundle RPC endpoint, which fails to properly enforce access controls based on the provided share link scope.\nThe vulnerability allows an attacker possessing a restrictive, low-privileged share link to bypass intended access boundaries. By exploiting the flaw, an attacker can enumerate all associated share-link records for a specific file, including secret IDs, page scopes, and elevated permission sets such as comment or inspection rights.\nThe impact is significant, as it facilitates privilege escalation and unauthorized information disclosure. An attacker can leverage the retrieved sensitive metadata to craft and replay a more permissive session token, subsequently gaining unauthorized access to protected page data or design resources beyond the scope of their original, limited access token.\nThis vulnerability poses a high risk to organizational data privacy, as it undermines the integrity of file-sharing permissions within collaborative design environments. Exploitation requires only a valid, restrictive share link and does not necessitate administrative or high-privileged authentication to the target instance.",
  "technicalDetails": "The vulnerability is localized within the get-view-only-bundle RPC function of the Penpot application. The root cause is a failure in the server-side authorization logic to validate that the requested resource scope strictly matches the permissions tied to the caller's specific share link token. Instead of returning only the bundle data relevant to the authenticated share link, the function improperly returns the entire collection of share-link rows associated with the target file.\nThe attack flow proceeds as follows: First, an attacker utilizes a restricted share link to initiate a connection to the Penpot platform. Upon calling the get-view-only-bundle RPC, the server fails to filter the response according to the privilege level of the provided link. The response includes an exhaustive list of metadata for the file, specifically exposing secret IDs for all other existing share links, associated page scopes, and granular permission objects like comment and inspection flags.\nEquipped with this leaked metadata, the attacker performs a secondary, malicious request. By replaying the discovered secret IDs or elevating their current session context using the leaked permission scope identifiers, the attacker successfully impersonates a user with higher authorization levels. This results in the server granting access to protected page data, inspection capabilities, or comment streams that were intended to be isolated from the original, restrictive share link context.\nThe vulnerable component is the RPC handler responsible for bootstrapping the view-only environment. The issue impacts all versions of Penpot prior to 2.18.0. Since the RPC endpoint can be accessed via standard network protocols, the vulnerability is externally exploitable by any actor who obtains a legitimate, albeit limited, link to a shared resource. The post-exploitation phase allows for the unauthorized retrieval of proprietary design assets, thereby bypassing the multi-tenant or role-based access control (RBAC) mechanisms designed to govern file sharing."
}
CVE-2026-105693: Penpot Improper Authorization Vulnerability (MEDIUM Severity, CVSS: 5.3) | Sceawere