Sceawere

Vulnerability Detail

CVE-2026-105631UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Plane Insecure Asset Access Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
3h ago
Vendor
makeplane
Product
plane
Attack Type
CWE-639: Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Plane is an open-source project management tool. Prior to 1.4.0, WorkspaceFileAssetEndpoint.get and WorkspaceAssetDownloadEndpoint.get resolve FileAsset records within a workspace without checking membership in the asset's project, allowing a workspace member to download assets from private projects when the asset UUID is known. EntityAssetEndpoint.get is a separate public-anchor endpoint that grants AllowAny access and scopes the lookup only to the anchor's workspace rather than its published entity or project. An unauthenticated caller who knows a valid anchor and an asset UUID can therefore retrieve issue-description or comment-description assets belonging to unpublished or private projects in that workspace. This issue is fixed in 1.4.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-05T18:17:36.427Z",
  "pubdate": "2026-10-05T18:17:36.427Z",
  "executiveSummary": "The Plane project management tool contains critical authorization bypass vulnerabilities in its file and asset handling endpoints, affecting versions prior to 1.4.0.\nThe vulnerability encompasses two distinct flaws: an internal workspace-level authorization bypass and a public-anchor-based unauthenticated disclosure vulnerability.\nThese flaws permit both authenticated workspace members and entirely unauthenticated remote attackers to retrieve sensitive project assets—such as issue descriptions and comments—from private or unpublished projects.\nThe root cause is a failure to perform project-level membership or scope validation during asset retrieval requests.\nAn attacker possessing the target asset UUID can bypass access controls to exfiltrate private internal documentation. The risk is significant, as it exposes confidential project information and intellectual property to unauthorized entities, including unauthenticated users if a valid anchor UUID is known.\nRemediation requires an immediate upgrade to version 1.4.0 or later to implement proper scoped authorization checks.",
  "technicalDetails": "The vulnerability consists of two primary attack vectors within the Plane application infrastructure involving improper access control validation during asset resolution.\nThe first vulnerability affects WorkspaceFileAssetEndpoint.get and WorkspaceAssetDownloadEndpoint.get. The root cause is the failure of these endpoints to perform cross-reference checks between the requested FileAsset and the associated Project membership. While these endpoints verify if a user belongs to the target workspace, they do not validate if the user has authorization for the specific private project containing the asset. Consequently, any authenticated workspace member can retrieve private assets if the specific UUID of the file is known.\nThe second, more severe vulnerability involves the EntityAssetEndpoint.get endpoint. This component functions as a public-anchor endpoint that utilizes an 'AllowAny' access policy. The application logic incorrectly scopes the lookup solely to the workspace associated with the anchor, rather than restricting access to the specific published entity or project. This represents a logic flaw in the authorization middleware.\nExploitation flow for the second vector: 1. An attacker identifies a target Workspace ID and a valid entity anchor. 2. The attacker performs a series of enumeration or discovery attempts (or leverages leaked UUIDs) to identify the target asset UUID associated with a private or unpublished project. 3. The attacker crafts a request to EntityAssetEndpoint.get using the known anchor and the targeted asset UUID. 4. The application logic, failing to check the ownership or privacy status of the underlying project, permits the retrieval of the file content based solely on the workspace-level anchor scope.\nThe affected components are WorkspaceFileAssetEndpoint, WorkspaceAssetDownloadEndpoint, and EntityAssetEndpoint. These flaws expose file assets regardless of their intended confidentiality level within the workspace structure. The lack of granular authorization allows for unauthorized data exfiltration, compromising the confidentiality of internal project metadata, descriptions, and comments. The vulnerability is confirmed to be present in all versions prior to 1.4.0, necessitating a migration to the patched version where proper project-scoping and session-based authorization checks are strictly enforced."
}
CVE-2026-105631: Plane Insecure Asset Access Vulnerability (HIGH Severity, CVSS: 7.5) | Sceawere