By vendor

Plane vulnerabilities

Known CVEs affecting Plane products, prioritized by severity, with SEC.co remediation and detection guidance.

1 published vulnerability

  • CVE-2026-46558HIGH 8.3

    Plane, an open-source project management platform, contains a critical authorization flaw that allows any logged-in user to access, modify, and delete files and assets stored in other workspaces they should not have permission to reach. This cross-workspace bypass persists in all versions prior to 1.3.1, making it a significant risk for organizations running multi-tenant Plane deployments where workspace isolation is expected to protect sensitive project data. The vulnerability requires authentication but no special privileges, meaning any team member can exploit it immediately.