← Volver a CVEs
CVE-2026-27706
HIGH7.7
Descripcion
Plane is an an open-source project management tool. Prior to version 1.2.2, a Full Read Server-Side Request Forgery (SSRF) vulnerability has been identified in the "Add Link" feature. This flaw allows an authenticated attacker with general user privileges to send arbitrary GET requests to the internal network and exfiltrate the full response body. By exploiting this vulnerability, an attacker can steal sensitive data from internal services and cloud metadata endpoints. Version 1.2.2 fixes the issue.
Detalles CVE
Puntuacion CVSS v3.17.7
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosLOW
Interaccion usuarioNONE
Publicado2/25/2026
Ultima modificacion2/27/2026
Fuentenvd
Avistamientos honeypot0
Productos afectados
plane:plane
Debilidades (CWE)
CWE-918
Referencias
https://github.com/makeplane/plane/releases/tag/v1.2.2(security-advisories@github.com)
https://github.com/makeplane/plane/security/advisories/GHSA-jcc6-f9v6-f7jw(security-advisories@github.com)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.