Plane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate workspace members and extract sensitive information including email addresses, user roles, and internal identifiers. The vulnerability stems from Django REST Framework permission classes being incorrectly configured to allow anonymous access to protected endpoints. This issue has been patched in version 1.2.2.
Metrics
Affected Vendors & Products
References
History
Fri, 06 Mar 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Plane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate workspace members and extract sensitive information including email addresses, user roles, and internal identifiers. The vulnerability stems from Django REST Framework permission classes being incorrectly configured to allow anonymous access to protected endpoints. This issue has been patched in version 1.2.2. | |
| Title | Plane: Unauthenticated Workspace Member Information Disclosure | |
| Weaknesses | CWE-200 CWE-284 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-03-06T21:19:12.962Z
Updated: 2026-03-06T21:19:12.962Z
Reserved: 2026-03-04T17:23:59.799Z
Link: CVE-2026-30244
No data.
Status : Received
Published: 2026-03-06T22:16:01.900
Modified: 2026-03-06T22:16:01.900
Link: CVE-2026-30244
No data.
ReportizFlow