VU#762226: Plane contains multi-tenant authorization bypass vulnerability
2026-07-21T20:52:07Z•c4d0c7bbe9057697cf07100281065157e829c941b9c3ddd210da571bea3e2eef
Android WebViewEd25519FTP PASVGNU WgetHTTP/2IOCTLRSA-PKCS1-v1.5SSL validation bypass','JavaScript injection','PayRangeSSRFSYSTEM escalationZeroMQauthorization-bypasscryptographydenial-of-servicedriverexpert-parallelflow-controlkernel-memorymobilemulti-tenantnode-forgepickle deserializationprivilege-escalationremote code executionsignature forgery
What happened
This collection of CERT/CC vulnerability notes describes multiple distinct vulnerabilities across open-source projects, libraries, and device drivers. Notable issues include: an authorization-bypass in Plane allowing cross‑workspace asset access/deletion (CVE-2026-15342); an HTTP/2 flow-control-induced remote DoS; an unauthenticated Pickle deserialization leading to RCE in SGLang’s expert-parallel backup subsystem (CVE-2026-14890); Pegatron tdeio64.sys IOCTLs permitting local kernel memory R/W and SYSTEM escalation (CVE-2026-14961, CVE-2026-14960); signature-forgery flaws in node-forge for RSA
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- c4d0c7bbe9057697cf07100281065157e829c941b9c3ddd210da571bea3e2eef
- Enrichment time
- 2026-07-21T20:52:07Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.