OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-105631

HIGH · CVSS 7.5 EPSS 0.24% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-05 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The vulnerability allows workspace members to access and download assets from private projects without proper membership verification, simply by knowing the asset UUID. This could lead to unauthorized disclosure of sensitive information, such as issue descriptions or comments from unpublished projects. Organizations using versions prior to 1.4.0 of the Plane project management tool should prioritize upgrading to mitigate potential data leaks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-105631
Severity
HIGH
CVSS
7.5
EPSS
0.24%

Original NVD Description

Plane is an open-source project management tool. Prior to 1.4.0, WorkspaceFileAssetEndpoint.get and WorkspaceAssetDownloadEndpoint.get resolve FileAsset records within a workspace without checking membership in the asset's project, allowing a workspace member to download assets from private projects when the asset UUID is known. EntityAssetEndpoint.get is a separate public-anchor endpoint that grants AllowAny access and scopes the lookup only to the anchor's workspace rather than its published entity or project. An unauthenticated caller who knows a valid anchor and an asset UUID can therefore retrieve issue-description or comment-description assets belonging to unpublished or private projects in that workspace. This issue is fixed in 1.4.0.