CVE-2026-46558
HIGHPlane: Cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane workspaces
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-46558. PoCs published by 0xmrma.
AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2026-46558, an authorization bypass vulnerability in Plane's V2 asset subsystem. The writeup includes root cause analysis, affected code paths, and a validated proof-of-concept demonstrating cross-workspace asset disclosure, copying, deletion, and overwrite.
Description
Plane is an open-source project management tool. Prior to version 1.3.1, there is a cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane workspaces. This issue has been patched in version 1.3.1.
Exploits (1)
This repository provides a detailed technical analysis of CVE-2026-46558, an authorization bypass vulnerability in Plane's V2 asset subsystem. The writeup includes root cause analysis, affected code paths, and a validated proof-of-concept demonstrating cross-workspace asset disclosure, copying, deletion, and overwrite.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L