CVE-2026-104971
Deferred Deferred - Pending Action

Plane Project Management Tool Multiple Authorization Bypass Vulnerabilities

Vulnerability report for CVE-2026-104971, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Plane is an open-source project management tool. Prior to 1.4.0, DuplicateAssetEndpoint fetches a source FileAsset without limiting it to the caller's workspace, allowing cross-workspace asset duplication. WorkspaceFileAssetEndpoint and the legacy FileAssetEndpoint omit workspace authorization, allowing authenticated users to read, create, modify, or delete assets in workspaces where they are not members. Separately, WorkspaceViewViewSet.retrieve lacks the authorization decorator used by its sibling actions, exposing an unauthorized workspace-view read surface. This issue is fixed in 1.4.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
makeplane plane < 1.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-104971 is a set of authorization vulnerabilities in Plane (versions <= 1.3.1) that allow unauthorized cross-workspace data access and file operations. The issues stem from missing or improper authorization checks in API endpoints like DuplicateAssetEndpoint, WorkspaceFileAssetEndpoint, and FileAssetEndpoint. These flaws enable users to duplicate, read, modify, or delete assets in workspaces where they are not members.

Detection Guidance

To detect this vulnerability, check Plane software versions for <=1.3.1. Review API endpoint access logs for unauthorized cross-workspace file operations or asset duplication attempts. Use commands like 'curl -X GET http://<plane-server>/api/workspaces/<workspace-slug>/assets' to test if non-members can access workspace assets. Monitor for unusual file creation, modification, or deletion events across workspaces.

Impact Analysis

An attacker could exploit these flaws to steal files, modify or delete assets, or duplicate files from other workspaces without permission. This could lead to data loss, unauthorized access to sensitive information, or disruption of workspace operations in multi-tenant deployments.

Compliance Impact

This vulnerability likely violates compliance requirements for data access controls in GDPR and HIPAA. It enables unauthorized access to sensitive data across workspaces, which could result in data breaches and non-compliance with privacy regulations requiring strict access controls and data segregation.

Mitigation Strategies
  • Upgrade Plane to version 1.4.0 or later to address the authorization vulnerabilities in asset endpoints and workspace checks.
  • Review and enforce workspace membership checks on all FileAsset and asset-related endpoints to prevent cross-workspace access.
  • Implement project-level scoping in asset queries to restrict access to authorized workspaces only.
  • Apply role-based restrictions, such as limiting workspace logo uploads to administrators only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104971. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart