CVE-2026-104967
Deferred Deferred - Pending Action

Stored Issue Manipulation in Plane Project Management Tool

Vulnerability report for CVE-2026-104967, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Plane is an open-source project management tool. Prior to 1.4.0, BulkDeleteIssuesEndpoint and SubIssuesEndpoint in apps/api/plane/app/views/issue/ accept body- or URL-supplied issue IDs and operate on them without checking that the IDs belong to the caller's workspace and project. The permission decorator on each endpoint validates only that the caller is a member or administrator of the workspace and project named in the URL. BulkDeleteIssuesEndpoint can destroy CycleIssue and ModuleIssue associations belonging to foreign issues. SubIssuesEndpoint can re-parent foreign issues under an attacker-selected issue and return the foreign issues' metadata. This issue is fixed in 1.4.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
makeplane plane < 1.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-104967 affects Plane, an open-source project management tool, versions prior to 1.4.0. It involves two vulnerabilities in the BulkDeleteIssuesEndpoint and SubIssuesEndpoint where endpoints accept issue IDs from the request body or URL without verifying they belong to the caller's workspace or project. This allows authenticated users to perform unauthorized actions across different workspaces.

Impact Analysis

An attacker with ROLE.ADMIN or ROLE.MEMBER privileges could delete or re-parent issues belonging to other workspaces, read metadata of foreign issues, or corrupt related records like CycleIssue and ModuleIssue. This could lead to data loss, unauthorized access to sensitive information, or disruption of project management operations.

Compliance Impact

This vulnerability could lead to unauthorized access or deletion of sensitive data, violating GDPR's data integrity and confidentiality principles or HIPAA's access controls. Organizations using affected Plane versions may face compliance violations, data breaches, and potential legal consequences.

Mitigation Strategies

Upgrade Plane to version 1.4.0 or later to address the vulnerability in BulkDeleteIssuesEndpoint and SubIssuesEndpoint. Ensure all instances are updated to prevent unauthorized cross-workspace actions and data corruption.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104967. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart