By vendor
Plane vulnerabilities
Known CVEs affecting Plane products, prioritized by severity, with SEC.co remediation and detection guidance.
1 published vulnerability
- CVE-2026-46558HIGH 8.3
Plane, an open-source project management platform, contains a critical authorization flaw that allows any logged-in user to access, modify, and delete files and assets stored in other workspaces they should not have permission to reach. This cross-workspace bypass persists in all versions prior to 1.3.1, making it a significant risk for organizations running multi-tenant Plane deployments where workspace isolation is expected to protect sensitive project data. The vulnerability requires authentication but no special privileges, meaning any team member can exploit it immediately.