CVE-2026-104965
Deferred Deferred - Pending Action

Plane Project Management Tool Issue Relation Privilege Escalation Vulnerability

Vulnerability report for CVE-2026-104965, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Plane is an open-source project management tool. Prior to 1.4.0, the issue-relation endpoint accepts issue UUIDs in the request body without validating that they belong to the caller's workspace. An authenticated user can create relations linking their own issues to issues in any other workspace on the instance, leaking issue metadata through activity events. This issue is fixed in 1.4.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
makeplane plane < 1.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an Insecure Direct Object Reference (IDOR) vulnerability in Plane versions before 1.4.0. It allows authenticated users to create issue relations linking their issues to issues in other workspaces without proper validation. The affected endpoint accepts issue UUIDs without checking workspace ownership, enabling cross-tenant data access.

Detection Guidance

To detect this vulnerability, check Plane server logs for unusual POST requests to the issue-relation endpoint with UUIDs from different workspaces. Look for activity events showing cross-workspace issue relations. Verify if users can access issue metadata outside their workspace.

Impact Analysis

An attacker could link their issues to yours, potentially leaking metadata like issue titles, statuses, or comments through activity events. This exposes sensitive project information across different workspaces on the same Plane instance.

Compliance Impact

This vulnerability could lead to unauthorized data exposure, violating confidentiality requirements in GDPR and HIPAA. It may result in non-compliance due to improper access controls allowing cross-workspace data leakage.

Mitigation Strategies

Upgrade Plane to version 1.4.0 or later to patch the vulnerability. Review server logs for past exploitation attempts. Restrict API access to trusted users and monitor for unauthorized cross-workspace relations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104965. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart