CVE-2026-105690
Last modified
CVE-2026-105690 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. Penpot is an open-source design and prototyping platform. Prior to 2.18.0, logout clears the browser's auth-token cookie without revoking the corresponding server-side session.
Description
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, logout clears the browser's auth-token cookie without revoking the corresponding server-side session. A previously captured session token remains usable after the victim logs out and can continue to make authenticated requests with the victim's authority until natural expiration. This issue is fixed in version 2.18.0.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-105690?
How severe is CVE-2026-105690?
How do I fix CVE-2026-105690?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-105684Penpot is an open-source design and prototyping platform. Pr…4.3
- CVE-2026-105686Penpot is an open-source design and prototyping platform. Pr…5.3
- CVE-2026-105687Penpot is an open-source design and prototyping platform. Pr…4.9
- CVE-2026-105688Penpot is an open-source design and prototyping platform. Pr…6.7
- CVE-2026-105689Penpot is an open-source design and prototyping platform. Pr…6
- CVE-2026-10569IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3…4.3
- CVE-2026-105691Penpot is an open-source design and prototyping platform. Pr…9.9
- CVE-2026-105692Penpot is an open-source design and prototyping platform. Pr…5.4
- CVE-2026-105693Penpot is an open-source design and prototyping platform. Pr…5.3
- CVE-2026-105694Penpot is an open-source design and prototyping platform. Pr…5.4
- CVE-2026-105695Penpot is an open-source design and prototyping platform. Pr…5.9
- CVE-2026-105696Penpot is an open-source design and prototyping platform. Pr…6.5
Are you affected by CVE-2026-105690?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
