Plane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate workspace members and extract sensitive information including email addresses, user roles, and internal identifiers. The vulnerability stems from Django REST Framework permission classes being incorrectly configured to allow anonymous access to protected endpoints. This issue has been patched in version 1.2.2.
History

Fri, 06 Mar 2026 21:30:00 +0000

Type Values Removed Values Added
Description Plane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate workspace members and extract sensitive information including email addresses, user roles, and internal identifiers. The vulnerability stems from Django REST Framework permission classes being incorrectly configured to allow anonymous access to protected endpoints. This issue has been patched in version 1.2.2.
Title Plane: Unauthenticated Workspace Member Information Disclosure
Weaknesses CWE-200
CWE-284
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-03-06T21:19:12.962Z

Reserved: 2026-03-04T17:23:59.799Z

Link: CVE-2026-30244

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-06T22:16:01.900

Modified: 2026-03-06T22:16:01.900

Link: CVE-2026-30244

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.