CVE-2026-104966
Deferred Deferred - Pending Action

Unauthorized Data Access in Plane Project Management Tool

Vulnerability report for CVE-2026-104966, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Plane is an open-source project management tool. Prior to 1.4.0, two endpoint families fail to verify that nested resource identifiers belong to the workspace and project named in the URL. An authenticated user can read or modify estimates from another workspace through PATCH /api/workspaces/{slug}/projects/{project_id}/estimates/{estimate_id}/, and can inject comments into an issue from another workspace through POST /api/workspaces/{slug}/projects/{project_id}/issues/{issue_id}/comments/. ProjectEntityPermission verifies membership in the workspace and project from the URL, but estimate_id and issue_id are fetched by primary key without confirming the same scope. The list, retrieve, and destroy handlers correctly scope their queries, demonstrating the inconsistency. This issue is fixed in 1.4.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
makeplane plane < 1.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-104966 is an Insecure Direct Object Reference (IDOR) vulnerability in the Plane project management tool affecting versions before 1.4.0. It involves two endpoints that fail to validate nested resource IDs against the specified workspace or project. This allows authenticated users to read, modify, or inject data across different workspaces. The first issue affects Estimate endpoints where estimates can be read or modified without proper scope validation. The second issue allows injecting comments into issues from other workspaces.

Detection Guidance

To detect this vulnerability, review Plane application logs for unauthorized access attempts to estimates or comments across different workspaces. Check for API requests to endpoints like PATCH /api/workspaces/{slug}/projects/{project_id}/estimates/{estimate_id}/ or POST /api/workspaces/{slug}/projects/{project_id}/issues/{issue_id}/comments/ with mismatched resource IDs. Ensure all nested resource IDs are validated against the workspace and project context.

Impact Analysis

This vulnerability allows authenticated users to access or modify data they shouldn't, such as reading all estimate data or injecting unauthorized comments into issues across different workspaces. It can lead to information disclosure, data modification, unauthorized actions, and data integrity violations. The impact includes potential exposure of sensitive project details and disruption of normal workflows.

Mitigation Strategies

Upgrade Plane to version 1.4.0 or later to apply the security fixes. If upgrading is not immediately possible, implement workspace and project validation checks for the affected endpoints. Restrict API access to trusted users and monitor for suspicious activity involving cross-workspace data access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104966. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart