CVE-2026-104894
Deferred Deferred - Pending Action

Unauthorized Issue Linking in Plane Prior to 1.4.0

Vulnerability report for CVE-2026-104894, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Plane is an open-source project management tool. Prior to 1.4.0, the modules endpoint accepts issue UUIDs in the URL path without validating that they belong to the caller's workspace. An authenticated user can link issues from any workspace to modules in their own workspace. This issue is fixed in 1.4.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
makeplane plane < 1.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-104894 is an Insecure Direct Object Reference (IDOR) vulnerability in the Plane project management tool. It affects versions prior to 1.4.0. The vulnerability allows authenticated users to link issues from any workspace to modules in their own workspace by manipulating issue UUIDs in the URL path without proper validation. This occurs because the modules endpoint fails to verify that the issue belongs to the caller's workspace.

Detection Guidance

To detect this vulnerability, check Plane application logs for unauthorized issue linking attempts or bulk operations involving issue IDs from different workspaces. Look for POST requests to /api/workspaces/<slug>/projects/<project_id>/issues/<issue_id>/modules/ with mismatched workspace scopes. Verify if users can access issues outside their assigned workspace.

Impact Analysis

An attacker could link private issues from other workspaces to their own modules, potentially causing metadata leakage through activity events. This could expose sensitive information about issues or projects not belonging to the attacker's workspace. The impact is limited to unauthorized data association rather than direct data modification or deletion.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR (data protection) and HIPAA (health information privacy). Unauthorized data association risks exposing personal or protected health information to unauthorized users, potentially resulting in regulatory penalties or breaches of confidentiality.

Mitigation Strategies

Upgrade Plane to version 1.4.0 or later immediately. Review API access logs for suspicious activity related to issue linking or bulk operations. Implement network-level monitoring for unauthorized cross-workspace data access attempts. Restrict API endpoints to enforce workspace and project scoping for all issue-related operations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104894. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart