← back
CVE-2026-30244

Plane: Unauthenticated Workspace Member Information Disclosure

CVSS 7.5 HIGHEPSS 0.4%CWE-200CWE-284
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.5EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
06 Mar 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Plane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate workspace members and extract sensitive information including email addresses, user roles, and internal identifiers. The vulnerability stems from Django REST Framework permission classes being incorrectly configured to allow anonymous access to protected endpoints. This issue has been patched in version 1.2.2.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
makeplane · plane

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →