Access Control Issue in Plane Project Management Tool
CVE-2026-105631
7.5HIGH
What is CVE-2026-105631?
The Plane project management tool has an access control issue allowing unauthorized users to download private project assets. Prior to version 1.4.0, certain endpoints did not validate user membership in respective projects. As a result, any workspace member could retrieve files from private projects, provided they had knowledge of the asset UUID. This vulnerability also extends to unauthenticated users who could access unpublished or private project assets by knowing a valid anchor and asset UUID, thereby compromising sensitive project information. This issue has been resolved in version 1.4.0.
Affected Version(s)
plane < 1.4.0
