CERT /CC issued an advisory on July 21, 2026, regarding a vulnerability in the Plane project management software, tracked as CVE-2026-15342. This vulnerability allows users in one workspace to access, modify, or delete files in another workspace due to a lack of access control checks in the asset-management API. Affecting versions 1.3.0 and earlier, the issue remains unpatched, raising concerns about potential data theft or loss. Although no confirmed exploitation has been observed, organizations are advised to implement API-gateways and logging to monitor suspicious activity.
Plane software flaw lets users steal files across workspaces
CyberSIXT Evidence Panel
Article by CyberSIXT