Authorization Flaw in Plane's Asset Management API
CVE-2026-15342
Currently unrated
What is CVE-2026-15342?
The Plane asset-management API has a multi-tenant authorization flaw that permits authenticated users within one workspace to access and manipulate assets from different workspaces. By leveraging the victim's workspace slug and asset ID, attackers can obtain presigned URLs, enabling unauthorized actions such as asset deletion and duplication. This vulnerability facilitates cross-tenant data exposure and may lead to persistent data exfiltration, jeopardizing the privacy and integrity of user assets across the platform.
Affected Version(s)
Plane 0 <= 1.3.0
