Authorization Flaw in Plane's Asset Management API
CVE-2026-15342

Currently unrated

Key Information:

Vendor

Plane

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2026-15342?

The Plane asset-management API has a multi-tenant authorization flaw that permits authenticated users within one workspace to access and manipulate assets from different workspaces. By leveraging the victim's workspace slug and asset ID, attackers can obtain presigned URLs, enabling unauthorized actions such as asset deletion and duplication. This vulnerability facilitates cross-tenant data exposure and may lead to persistent data exfiltration, jeopardizing the privacy and integrity of user assets across the platform.

Affected Version(s)

Plane 0 <= 1.3.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.