8.3
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Description
CVE-2026-46558 Plane’s V2 asset subsystem trusted workspace slugs and asset UUIDs without enforcing the right membership checks, which let one authenticated user read, copy, delete, and overwrite assets in other workspaces. Intro I found this issue...
Basic Information
ID
22CFEBF4-738A-52AD-B1A9-E066D3D33C80
Published
Jun 26, 2026 at 12:57
Modified
Jun 26, 2026 at 12:59