A vulnerability was found in Penpot up to 2.17.0. It has been rated as critical. The impacted element is the function
import-binfile of the component Import. This manipulation of the argument file-id causes missing authorization.
The identification of this vulnerability is CVE-2026-17613. It is possible to initiate the attack remotely. There is no exploit available.