CVE-2026-104968
Deferred Deferred - Pending Action

Plane Project Management Tool Information Exposure Vulnerability

Vulnerability report for CVE-2026-104968, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Plane is an open-source project management tool. Prior to 1.4.0, GET /api/workspaces/{slug}/entity-search/?query_type=user_mention returns workspace-member display names, UUIDs, and avatar URLs to any authenticated user who knows the workspace slug, even when the caller is not a workspace member. The endpoint also exposes ProjectMember rows under the same condition. SearchEndpoint in apps/api/plane/app/views/search/base.py inherits BaseAPIView with only permission_classes = [IsAuthenticated] and performs no workspace-membership check. This issue is fixed in 1.4.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
makeplane plane < 1.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Plane (versions <= 1.3.1) allows any authenticated user to access workspace member details (display names, UUIDs, avatar URLs) for any workspace by guessing its slug, even without being a member. The /api/workspaces/{slug}/entity-search/ endpoint only required authentication but did not check workspace membership, enabling cross-workspace member enumeration.

Detection Guidance

To detect this vulnerability, check if your Plane instance is running a version prior to 1.4.0. Use commands like 'curl -X GET "http://<plane-server>/api/workspaces/<workspace-slug>/entity-search/?query_type=user_mention" -H "Authorization: Bearer <token>"' to test if unauthorized users can access workspace member data. If the endpoint returns member details without proper workspace membership verification, the system is vulnerable.

Impact Analysis

An attacker could enumerate all members of any workspace they know the slug for, exposing sensitive user data. This could lead to targeted phishing, social engineering, or further attacks against specific users. The risk is higher on Plane Cloud due to open self-signup allowing unauthenticated enumeration.

Compliance Impact

This vulnerability likely violates GDPR's data minimization and security principles by exposing personal data without proper authorization. It may also conflict with HIPAA's access control requirements for protected health information if workspace members include healthcare professionals.

Mitigation Strategies

Immediately upgrade Plane to version 1.4.0 or later to apply the security fix. If upgrading is not immediately possible, restrict access to the /api/workspaces/{slug}/entity-search/ endpoint by implementing network-level controls or temporary firewall rules until the upgrade is completed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104968. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart