← לוח פגיעויות

CVE-2026-46558

גבוהה 8.3

תיאור (מקור, אנגלית)

Plane is an open-source project management tool. Prior to version 1.3.1, there is a cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane workspaces. This issue has been patched in version 1.3.1.

מדדים

CVSS 3.1
8.3 (HIGH) מקור הציון: CNA CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-10/8/2026
CWE
CWE-639, CWE-862

מוצרים מושפעים

plane: plane

קישורים