๐Ÿ” CVE Alert

CVE-2026-104966

UNKNOWN 0.0

Plane: Cross-Workspace IDOR in Estimate and Comment Endpoints Allows Read, Modify, and Inject Across Workspaces

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Plane is an open-source project management tool. Prior to 1.4.0, two endpoint families fail to verify that nested resource identifiers belong to the workspace and project named in the URL. An authenticated user can read or modify estimates from another workspace through PATCH /api/workspaces/{slug}/projects/{project_id}/estimates/{estimate_id}/, and can inject comments into an issue from another workspace through POST /api/workspaces/{slug}/projects/{project_id}/issues/{issue_id}/comments/. ProjectEntityPermission verifies membership in the workspace and project from the URL, but estimate_id and issue_id are fetched by primary key without confirming the same scope. The list, retrieve, and destroy handlers correctly scope their queries, demonstrating the inconsistency. This issue is fixed in 1.4.0.

CWE CWE-639
Vendor makeplane
Product plane
Published Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for makeplane plane

Be the first to know when new unknown vulnerabilities affecting makeplane plane are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

makeplane / plane
< 1.4.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/makeplane/plane/security/advisories/GHSA-933r-rxg8-f3h2 github.com: https://github.com/makeplane/plane/pull/9286 github.com: https://github.com/makeplane/plane/commit/971c2aadb4e848d70676b4f58b94bc7992dfe5fc github.com: https://github.com/makeplane/plane/releases/tag/v1.4.0