Cross-Workspace Authorization Bypass in Plane Project Management Tool
CVE-2026-46558
8.3HIGH
What is CVE-2026-46558?
An authorization bypass vulnerability in the Plane project management tool allows authenticated users to access, modify, and delete assets across different workspaces. This significant flaw exposes sensitive information and compromises workspace integrity, making it essential for users to upgrade to version 1.3.1 or later to mitigate the risk.
Affected Version(s)
plane < 1.3.1
