CVE-2026-105629
Deferred Deferred - Pending Action

Cross-Tenant IDOR in Plane Project Management Tool

Vulnerability report for CVE-2026-105629, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Plane is an open-source project management tool. Prior to 1.4.0, BulkEstimatePointEndpoint.destroy resolves an estimate point through a bare primary-key lookup without workspace, project, or estimate scoping. An administrator or member of one workspace can permanently delete an estimate point belonging to another workspace by supplying the target UUID in a URL under the attacker's own workspace. This creates a destructive cross-tenant IDOR. This issue is fixed in 1.4.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
makeplane plane < 1.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105629 is a cross-tenant Insecure Direct Object Reference (IDOR) vulnerability in the Plane project management tool. It allows authenticated users (admins or members) in one workspace to permanently delete estimate points belonging to another workspace by exploiting improper scoping in the BulkEstimatePointEndpoint.destroy function. The vulnerability arises because the endpoint resolves estimate points using only a primary-key lookup without verifying workspace, project, or estimate ownership.

Detection Guidance

To detect this vulnerability, check Plane instances running versions <= 1.3.1 for unauthorized deletion attempts in logs. Look for API calls to /api/estimate-points/bulk/destroy with UUIDs not belonging to the requester's workspace. Monitor for sudden disappearance of estimate points across different workspaces.

Impact Analysis

If you use Plane versions 1.3.1 or earlier, an attacker with access to your instance could delete critical estimate points belonging to other workspaces or projects. This could disrupt project planning, cause data loss, and affect collaboration across teams. The impact includes high integrity compromise and low availability disruption.

Compliance Impact

This vulnerability could lead to unauthorized data deletion, violating integrity and availability requirements in GDPR and HIPAA. GDPR requires data integrity and protection against unauthorized destruction, while HIPAA mandates safeguards to prevent unauthorized access or alteration of protected health information. Exploiting this flaw may result in non-compliance.

Mitigation Strategies

Upgrade Plane to version 1.4.0 or later immediately. If upgrading is not possible, restrict access to the BulkEstimatePointEndpoint.destroy endpoint temporarily. Review logs for signs of exploitation and revoke access for any suspicious accounts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105629. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart