Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-44986: Penpot: Unsecured Account Takeover via Invitation Token
CVE-2026-44986
CVE-2026-44986
Summary
Penpot, a design tool, had a security weakness that allowed a registered user to take over any non-blocked account by using an invitation token. This meant that an attacker could gain access to sensitive information and potentially disrupt design and code collaboration. Penpot has since fixed this issue in version 2.14.5, so it's essential to update to the latest version to ensure security.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| penpot | penpot | < 2.14.5 |
Original title
Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from create-team-invitations, embedded an existing pr...
Original description
Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from create-team-invitations, embedded an existing profile id in auth.clj prepare-register-profile, and had auth.clj register-profile issue a session based on the invitation email match without password verification, allowing a registered user to take over any non-blocked profile. This issue is fixed in version 2.14.5.
mitre CVSS3.1
9.9
Vulnerability type
CWE-287
Improper Authentication
CWE-639
Authorization Bypass Through User-Controlled Key
- https://github.com/penpot/penpot/security/advisories/GHSA-4937-35vc-hqjj x_refsource_CONFIRM
- https://github.com/penpot/penpot/pull/9380 x_refsource_MISC
- https://github.com/penpot/penpot/commit/9e681260ccc4feb6c564ff0773fb9594b462c574 x_refsource_MISC
- https://github.com/penpot/penpot/releases/tag/2.14.5 x_refsource_MISC
Published: 15 Jul 2026 · Updated: 20 Jul 2026 · First seen: 15 Jul 2026