CVE-2026-104975
Deferred Deferred - Pending Action

Plane Asset IDOR in Public Board Operations

Vulnerability report for CVE-2026-104975, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Plane is an open-source project management tool. Prior to 1.4.0, Plane's dashboard asset endpoints in plane/app/views/asset/v2.py were remediated for two cross-tenant asset IDORs, CVE-2026-27705 and CVE-2026-46558. Those fixes added a membership check and project_id and workspace__slug scoping to the asset endpoints in that file. The Spaces app in plane/space/views/asset.py serves related public-board operations under /api/public/ but was not remediated. Its EntityAssetEndpoint and AssetRestoreEndpoint resolve a DeployBoard from a public anchor and then read or modify FileAsset rows scoped only to the board's workspace, without a membership check or project_id constraint. An attacker can therefore read, overwrite, or restore assets across projects and workspaces. This issue is fixed in 1.4.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
makeplane plane < 1.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-104975 is a high-severity vulnerability in Plane's Spaces public-board endpoints that allows cross-tenant asset authorization bypass. It affects Plane versions 1.3.1 and earlier. The issue stems from improper authorization checks in the Spaces app (plane/space/views/asset.py), which does not enforce membership or project scoping unlike remediated dashboard endpoints.

Detection Guidance

To detect this vulnerability, check Plane versions for 1.3.1 or earlier. Inspect plane/space/views/asset.py for missing @allow_permission decorators and lack of project_id/workspace scoping in EntityAssetEndpoint and AssetRestoreEndpoint. Review logs for unauthorized asset access or modification attempts across workspaces.

Impact Analysis

An attacker could exploit this to read, overwrite, or restore assets across different projects and workspaces. This includes accessing private project images via presigned URLs, modifying asset metadata, or restoring deleted assets without proper permissions. Exploitation requires knowledge of target asset UUIDs and victim workspace tokens.

Compliance Impact

This vulnerability breaks workspace and project isolation, potentially leading to unauthorized access to sensitive data. This could violate compliance requirements for data protection and access controls in standards like GDPR and HIPAA, which mandate strict access boundaries and data segregation.

Mitigation Strategies

Upgrade Plane to version 1.4.0 or later immediately. Apply the same remediation from plane/app/views/asset/v2.py to plane/space/views/asset.py by adding membership checks, project_id scoping, and @allow_permission decorators to the Spaces endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104975. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart