CVE-2026-27706

HIGH

Plane < 1.2.2 - Authenticated Server-Side Request Forgery via Add Link Feature

Title source: llm
STIX 2.1

Description

Plane is an an open-source project management tool. Prior to version 1.2.2, a Full Read Server-Side Request Forgery (SSRF) vulnerability has been identified in the "Add Link" feature. This flaw allows an authenticated attacker with general user privileges to send arbitrary GET requests to the internal network and exfiltrate the full response body. By exploiting this vulnerability, an attacker can steal sensitive data from internal services and cloud metadata endpoints. Version 1.2.2 fixes the issue.

References (2)

Core 2
Core References

Scores

CVSS v3 7.7
EPSS 0.0021
EPSS Percentile 11.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (1)
plane/plane < 1.2.2
Published Feb 25, 2026
Tracked Since Feb 26, 2026