ProjectAssetEndpoint.patch of the file apps/api/plane/app/views/asset/v2.py. Performing a manipulation results in authorization bypass.This vulnerability is cataloged as CVE-2026-27705. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
SOCIAL SHARE CARD GENERATOR