CVE-2026-105633
Deferred Deferred - Pending Action

Privilege Escalation in Plane Project Management Tool

Vulnerability report for CVE-2026-105633, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Plane is an open-source project management tool. Prior to 1.4.0, the V2 issue-attachment PATCH endpoint accepts issue_id in the URL but omits it from the database query. A project member can use an issue_id they control in the URL while targeting another user's attachment by its pk UUID. Because the server matches only pk, workspace, and project_id, it modifies the attachment regardless of the issue_id in the URL. When the attachment is pending and has not been confirmed as uploaded, the PATCH handler sets created_by = request.user and transfers attachment ownership to the attacker. This issue is fixed in 1.4.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
makeplane plane < 1.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105633 is a high-severity authorization bypass in Plane's Issue Attachment V2 API. The PATCH endpoint accepts an issue_id in the URL but omits it from the database query. An attacker can use their own issue_id in the URL while targeting another user's attachment via its UUID. For pending attachments, the system sets created_by to the attacker, transferring ownership and granting delete rights while revoking them from the original uploader.

The vulnerability corrupts the audit trail by falsifying the created_by field in activity logs. It requires two accounts in the same project with the attacker having MEMBER role. The issue was patched in Plane version 1.4.0.

Detection Guidance

Detecting this vulnerability requires checking Plane versions and monitoring for unauthorized attachment ownership changes. Verify installed Plane version with 'pip show plane' or check deployment logs. Inspect API logs for PATCH requests to /api/v2/issue-attachments/ with mismatched issue_id and attachment UUIDs. Look for sudden ownership transfers in attachment metadata.

Impact Analysis

An attacker could hijack ownership of your pending file attachments, preventing you from deleting your own files. They could then delete the files, causing permanent data loss. Your audit logs would incorrectly show the attacker as the creator of the files.

The attacker needs to be a project member with MEMBER role and have access to your attachment UUID. The exploit requires two accounts in the same project.

Compliance Impact

This vulnerability could violate compliance requirements by allowing unauthorized access to or deletion of sensitive data. It may compromise data integrity and audit trails, which are critical for GDPR and HIPAA compliance. Unauthorized ownership changes could lead to improper data handling and reporting.

Mitigation Strategies

Upgrade Plane to version 1.4.0 or later immediately. If upgrading is not possible, restrict project member permissions to minimum required roles. Monitor all issue attachments for unauthorized ownership changes and revoke any suspicious transfers. Review audit logs for DELETE operations on attachments not initiated by original uploaders.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105633. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart