CVE-2026-46558

HIGH

Plane: Cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane workspaces

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-46558. PoCs published by 0xmrma.

AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2026-46558, an authorization bypass vulnerability in Plane's V2 asset subsystem. The writeup includes root cause analysis, affected code paths, and a validated proof-of-concept demonstrating cross-workspace asset disclosure, copying, deletion, and overwrite.

Description

Plane is an open-source project management tool. Prior to version 1.3.1, there is a cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane workspaces. This issue has been patched in version 1.3.1.

Exploits (1)

github WRITEUP
by 0xmrma · poc
https://github.com/0xmrma/CVE-2026-46558

This repository provides a detailed technical analysis of CVE-2026-46558, an authorization bypass vulnerability in Plane's V2 asset subsystem. The writeup includes root cause analysis, affected code paths, and a validated proof-of-concept demonstrating cross-workspace asset disclosure, copying, deletion, and overwrite.

Classification
Writeup 100%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Plane Community Edition 1.2.3
Auth required
Prerequisites: authenticated user account in a workspace · valid asset UUID from another workspace
mistral-large-3 · analyzed Jun 26, 2026 Full analysis →

References (2)

Core 2
Core References
X_Refsource_Misc x_refsource_misc
https://github.com/makeplane/plane/releases/tag/v1.3.1

Scores

CVSS v3 8.3
EPSS 0.0028
EPSS Percentile 20.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-639 CWE-862
Status published
Products (2)
makeplane/plane < 1.3.1
plane/plane < 1.3.1
Published Jun 10, 2026
Tracked Since Jun 10, 2026