Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or duplicate assets belonging to another workspace by providing only the victim workspace slug and asset ID. The affected endpoints return presigned file URLs and enable destructive or duplicative actions without verifying that the requester is a member of the targeted workspace. This enables cross‑tenant data exposure, data deletion, and persistent exfiltration of files into an attacker‑controlled workspace.
Metrics
Affected Vendors & Products
References
History
Wed, 22 Jul 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-552 CWE-639 |
|
| Metrics |
cvssV3_1
|
Tue, 21 Jul 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Plane
Plane plane |
|
| Vendors & Products |
Plane
Plane plane |
Tue, 21 Jul 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or duplicate assets belonging to another workspace by providing only the victim workspace slug and asset ID. The affected endpoints return presigned file URLs and enable destructive or duplicative actions without verifying that the requester is a member of the targeted workspace. This enables cross‑tenant data exposure, data deletion, and persistent exfiltration of files into an attacker‑controlled workspace. | |
| Title | CVE-2026-15342 | |
| References |
|
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-07-22T19:01:12.727Z
Reserved: 2026-07-09T20:03:50.205Z
Link: CVE-2026-15342
Updated: 2026-07-21T17:30:27.096Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-21T22:45:02Z