PT-2026-106028 · Plane · Plane

·

CVE-2026-104960

·

Published

2026-10-05

·

Updated

2026-10-05

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Plane versions prior to 1.4.0
Description An authentication bypass allows users within the same workspace to access private file content from secret projects they are not members of. This occurs because the workspace-scoped endpoint '/api/assets/v2/workspaces/{workspace slug}/download/{asset id}/' fails to enforce access restrictions for project-bound FileAsset objects. An authenticated user who knows the target asset id can trigger a 302 redirect to a signed download URL. This issue affects asset types including ISSUE ATTACHMENT, COMMENT DESCRIPTION, PAGE DESCRIPTION, and PROJECT COVER.
Recommendations Update to version 1.4.0.

Exploit

Fix

IDOR

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-104960
GHSA-WRRW-WVFV-67H7

Affected Products

Plane