Junglewise Threat Intelligence

CVE-2026-15342: Plane multi-tenant authorization bypass in asset-management API

CVE-2026-15342 · Severity: info · CVSS 0 · Published 2026-07-21

Executive brief

Plane is an open-source project management platform used by teams to track tasks, sprints, and workflows. A security flaw in the platform's file management system allows a user from one organization to access, copy, or delete files belonging to a completely different organization. This could lead to the theft of sensitive project documents or the permanent loss of data if an attacker deletes files from a victim's workspace.

Technical details

Plane versions 1.3.0 and earlier contain an Insecure Direct Object Reference (IDOR) / Broken Object Level Authorization (BOLA) vulnerability in the asset-management API. The affected endpoints accept workspace slugs and asset identifiers as path parameters but fail to verify if the authenticated requester is a member of the targeted workspace. An attacker with valid credentials for any workspace can access presigned URLs for files, delete assets, or duplicate them into their own workspace by supplying a victim's workspace slug and asset ID. As of the advisory date, no patch is available as the vendor could not be reached for coordination.

Affected products

  • Plane Plane <= 1.3.0

Timeline

  • 2026-05-28: other: Vendor notified by CERT/CC
  • 2026-07-21: disclosed: Public disclosure via CERT/CC and NVD

References