PT-2026-23619 · Plane · Plane

Sanu1999

·

Published

2026-03-05

·

Updated

2026-03-10

·

CVE-2026-30244

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Plane versions prior to 1.2.2
Description An issue exists in Plane that allows unauthenticated attackers to enumerate workspace members and extract sensitive information, including email addresses, user roles, and internal identifiers. This is due to incorrectly configured Django REST Framework permission classes allowing anonymous access to protected endpoints. Attackers can enumerate all members of any workspace without authentication, extract user email addresses and personally identifiable information, identify administrative accounts, map organizational structure, and conduct reconnaissance for social engineering attacks. The affected API endpoints are: /api/public/workspaces/{workspace slug}/members/ and /api/public/workspaces/{workspace slug}/projects/{project id}/members/. The vulnerable parameter is workspace slug.
Recommendations Update to version 1.2.2 or later.

Exploit

Fix

Improper Access Control

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2026-30244
GHSA-87X4-J8VH-P5QF

Affected Products

Plane