Security Advisory

CVE-2026-17613

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-05 14:12:03
Last updated 2026-08-05 16:01:24
Assigner certcc
CVSS score not scored
State PUBLISHED

Description

Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated user to overwrite any files on the target server and subscribe to WebSocket events, enabling full data exfiltration and data poisoning.