Vulnerability intelligence
CVE-2026-15342
Plane Plane
Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or duplicate assets belonging to another workspace by providing only the victim workspace slug and asset ID. The affected endpoints return presigned file URLs and enable destructive or duplicative actions without verifying that the requester is a member of the targeted workspace. This enables cross‑tenant data exposure, data deletion, and persistent exfiltration of files into an attacker‑controlled workspace.
CVSS Score
6.5
Medium
EPSS — Exploit Probability
0.4%
Riskier than 31% of all CVEs · checked 2026-09-10
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
1 article across 1 outlet · first covered Jul 27, 2026 · latest Jul 27, 2026
Coverage timeline
-
Plane software flaw lets users steal files across workspacessecurityonline.info · Jul 27, 2026