External risk intelligence

Plane Project Asset Reassignment Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-105637

Plane is an open-source project management tool typically deployed as a web application. Such applications are commonly hosted as internet-facing services to allow team collaboration and remote access, making the API endpoints involved in this vulnerability commonly reachable from the public internet.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a security vulnerability in the open-source project management tool, Plane. The issue could allow a user with limited access to potentially hijack files within the same workspace, leading to unauthorized access to sensitive information. The main concern is confirming relevance and exposure within your deployed instances.

  • Unauthorized file access in project management.
  • Protects against data misuse by unauthorized users.
  • Confirm if this tool is in use.

Attack Path

How an attacker could exploit the issue

An attacker with limited access can exploit this vulnerability by tricking the Plane application into misdirecting file downloads. By manipulating asset IDs and workspace information, an attacker can cause the application to believe that assets belong to their own project, leading to unauthorized access to sensitive files.

  • Requires network access and low privilege.
  • Triggers by reassigning asset ownership.
  • Risk of sensitive data exposure and modification.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, a workspace Guest could potentially reassign assets belonging to another project within the same workspace to an entity they control. This could lead to the attacker gaining access to download URLs for files that do not belong to them.

  • Project assets at risk.
  • Guest reassigns asset ownership.
  • Attacker downloads sensitive files.

Operational Fix

Recommended remediation, mitigation, and detection steps

Security teams and platform owners are likely responsible for addressing this vulnerability in the Plane project management tool. The first practical step is to identify all Plane instances within your environment, confirm their network exposure and business criticality, and then locate the accountable owner. A risk-based remediation plan should follow, prioritizing critical and exposed instances.

  • Platform or application owners should own the issue.
  • Verify Plane instance reachability and criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Plane and how is it used?

Plane is an open-source project management platform designed to help teams organize workflows, track issues, and manage project documentation. It functions as a web-based application where users collaborate within shared workspaces, storing various digital assets and project files that are managed through its API.

What is the vulnerability in CVE-2026-105637?

This vulnerability is classified as CWE-639, or Authorization Bypass Through User-Controlled Key. It occurs because the software fails to properly verify if a user has permission to access specific files. By manipulating identifiers in a request, a user can trick the system into reassigning the ownership of files to a project they control, granting them unauthorized access.

How can an attacker trigger this bug?

An attacker needs a low-privileged account, such as a workspace Guest, to trigger this flaw. By sending a specially crafted request with specific asset and workspace identifiers, they can bypass ownership checks. This does not trigger if the user lacks access to the workspace or if the asset identifiers are invalid.

Who should be concerned about this vulnerability?

Anyone running Plane is potentially at risk, especially since Halo Surface Signal notes that such tools are typically deployed as internet-facing web applications. Because these services are often reachable from the public internet to facilitate remote team collaboration, the API endpoint involved is likely accessible to external actors.

How do I secure my environment against this?

Your first step is to locate all active Plane instances within your infrastructure and confirm their version numbers. Since this issue is resolved in version 1.4.0, you should prioritize upgrading any outdated deployments to this release or newer to eliminate the flaw and protect your project assets.

References