CVE-2026-100868 | Penpot up to 2.17.x MCP server plugin WebSocket bridge improper authentication

SecurityVulns

A vulnerability classified as critical has been found in Penpot up to 2.17.x. Impacted is an unknown function of the component MCP server plugin WebSocket bridge. This manipulation causes improper authentication.

The identification of this vulnerability is CVE-2026-100868. It is possible to initiate the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More