CVE-2026-104964
Deferred Deferred - Pending Action

Plane Project Management Tool Tenant Isolation Bypass

Vulnerability report for CVE-2026-104964, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Plane is an open-source project management tool. Prior to 1.4.0, Plane's project update endpoint authorizes the caller against the workspace slug in the request URL but loads the target project globally by UUID without binding it to that workspace. An administrator of one workspace can modify a project in another workspace when the victim project UUID is known. This violates tenant isolation and permits unauthorized cross-workspace changes to project metadata and configuration. This issue is fixed in 1.4.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
makeplane plane < 1.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-104964 is a tenant isolation flaw in Plane, an open-source project management tool. It allows an administrator in one workspace to modify a project in another workspace if they know the victim project's UUID. The issue occurs because the project update endpoint checks workspace access via URL slug but loads projects globally by UUID, bypassing proper workspace scoping.

Detection Guidance

Check Plane software version. If running a version prior to 1.4.0, the system is vulnerable. Inspect API logs for unauthorized project modification attempts across workspaces, particularly involving UUIDs from different workspaces.

Impact Analysis

An attacker with admin rights in their workspace could change project metadata, configurations, or estimates in another workspace if they know the target project's UUID. This could disrupt projects, alter settings, or expose sensitive data, though it requires high privileges and UUID knowledge.

Compliance Impact

This vulnerability violates tenant isolation, potentially allowing unauthorized access to project data across workspaces. This could lead to breaches of confidentiality requirements in GDPR or HIPAA, as sensitive project information might be exposed or altered without proper authorization.

Mitigation Strategies

Upgrade Plane to version 1.4.0 or later immediately. Review recent project changes for unauthorized modifications. Ensure workspace isolation is enforced in API endpoints by verifying project UUIDs belong to the requested workspace.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104964. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart