Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-44986: Penpot: Unsecured Account Takeover via Invitation Token

CVE-2026-44986 CVE-2026-44986
Summary

Penpot, a design tool, had a security weakness that allowed a registered user to take over any non-blocked account by using an invitation token. This meant that an attacker could gain access to sensitive information and potentially disrupt design and code collaboration. Penpot has since fixed this issue in version 2.14.5, so it's essential to update to the latest version to ensure security.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
penpot penpot < 2.14.5
Original title
Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from create-team-invitations, embedded an existing pr...
Original description
Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from create-team-invitations, embedded an existing profile id in auth.clj prepare-register-profile, and had auth.clj register-profile issue a session based on the invitation email match without password verification, allowing a registered user to take over any non-blocked profile. This issue is fixed in version 2.14.5.
mitre CVSS3.1 9.9
Vulnerability type
CWE-287 Improper Authentication
CWE-639 Authorization Bypass Through User-Controlled Key
Published: 15 Jul 2026 · Updated: 20 Jul 2026 · First seen: 15 Jul 2026