CVE-2026-105631 | Makeplane Plane up to 1.3.x Asset Retrieval Endpoints access control

SecurityVulns

A vulnerability labeled as problematic has been found in Makeplane Plane up to 1.3.x. Impacted is the function WorkspaceFileAssetEndpoint.get/WorkspaceAssetDownloadEndpoint.get/EntityAssetEndpoint.get of the component Asset Retrieval Endpoints. The manipulation results in improper access controls.

This vulnerability is reported as CVE-2026-105631. The attack can be launched remotely. No exploit exists.

The affected component should be upgraded.VulDB Recent EntriesRead More