CVE-2026-15342
Received Received - Intake

Multi-Tenant Authorization Flaw in Plane Asset-Management API

Vulnerability report for CVE-2026-15342, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-21

Last updated on: 2026-07-21

Assigner: CERT/CC

Description

Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or duplicate assets belonging to another workspace by providing only the victim workspace slug and asset ID. The affected endpoints return presigned file URLs and enable destructive or duplicative actions without verifying that the requester is a member of the targeted workspace. This enables cross‑tenant data exposure, data deletion, and persistent exfiltration of files into an attacker‑controlled workspace.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-21
Last Modified
2026-07-21
Generated
2026-07-21
AI Q&A
2026-07-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
makeplane plane 1.3.0
makeplane plane to 1.3.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a multi-tenant authorization flaw in Plane's asset-management API. It allows authenticated users from one workspace to access, delete, or duplicate assets belonging to another workspace by providing only the victim workspace slug and asset ID. The affected endpoints return presigned file URLs and enable destructive or duplicative actions without verifying workspace membership.

Detection Guidance

Monitor API logs for cross-workspace asset requests. Check for unusual file URL generation or asset duplication/deletion events. Use network traffic analysis to detect unauthorized access patterns between workspaces.

Impact Analysis

An attacker could exfiltrate sensitive files, destroy project data, or create permanent copies of your assets. They only need to authenticate to any Plane workspace and know your workspace slug and asset ID, which may be obtainable from public sources.

Compliance Impact

This vulnerability could lead to unauthorized access or deletion of sensitive data, violating GDPR's data protection principles or HIPAA's confidentiality requirements. It enables cross-tenant data exposure, which may result in non-compliance with these regulations.

Mitigation Strategies

Implement API-gateway rules to block cross-workspace requests. Restrict firewall access to the asset-management API. Enable detailed activity logging and set up security alerts for suspicious cross-workspace actions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15342. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart