Access Control Issue in Plane Project Management Tool
CVE-2026-105631

7.5HIGH

Key Information:

Vendor

Makeplane

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105631?

The Plane project management tool has an access control issue allowing unauthorized users to download private project assets. Prior to version 1.4.0, certain endpoints did not validate user membership in respective projects. As a result, any workspace member could retrieve files from private projects, provided they had knowledge of the asset UUID. This vulnerability also extends to unauthenticated users who could access unpublished or private project assets by knowing a valid anchor and asset UUID, thereby compromising sensitive project information. This issue has been resolved in version 1.4.0.

Affected Version(s)

plane < 1.4.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.