Description
Plane is an open-source project management tool. Prior to 1.4.0, the modules endpoint accepts issue UUIDs in the URL path without validating that they belong to the caller's workspace. An authenticated user can link issues from any workspace to modules in their own workspace. This issue is fixed in 1.4.0.
Published: 2026-10-05
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Issue Linking Across Workspaces
Action: Patch Immediately
AI Analysis

Impact

The Plane project management platform allowed users to include issue UUIDs from any workspace when accessing the modules endpoint. Because the endpoint did not verify that the specified UUID belonged to the authenticated user's workspace, a user could associate an issue that resides in a different tenant into a module in their own workspace. This cross‑tenant link is possible for any authenticated user. The weakness is categorized as a broken access control (CWE‑639).

Affected Systems

This flaw affects all installations of Plane prior to release version 1.4.0. Users running any older version of the open‑source project management tool are potentially exposed. The fix was applied in the 1.4.0 release and subsequent revisions.

Risk and Exploitability

The CVSS score of 4.3 indicates low‑to‑moderate severity, and no EPSS data is available, implying no known public exploitation. The vulnerability is not listed in CISA’s KEV catalog. The attack vector requires an authenticated user; an attacker could create or link issues across tenants to gain visibility into other tenants’ data via the linking feature. However, the impact is limited to unauthorized association of issues, and does not grant arbitrary read or write access outside module linking. Nevertheless, the cross‑tenant exposure could lead to data leakage or confusion in project organization.

Generated by OpenCVE AI on October 5, 2026 at 18:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Plane to version 1.4.0 or later to apply the IDOR fix.
  • Implement application‑level checks that validate an issue UUID belongs to the caller’s workspace before linking it to a module.
  • If an upgrade is not possible immediately, consider disabling cross‑tenant issue linking or monitor for unauthorized link creation.

Generated by OpenCVE AI on October 5, 2026 at 18:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Makeplane
Makeplane plane
Vendors & Products Makeplane
Makeplane plane

Mon, 05 Oct 2026 17:00:00 +0000

Type Values Removed Values Added
Description Plane is an open-source project management tool. Prior to 1.4.0, the modules endpoint accepts issue UUIDs in the URL path without validating that they belong to the caller's workspace. An authenticated user can link issues from any workspace to modules in their own workspace. This issue is fixed in 1.4.0.
Title Plane: Cross-Tenant Module Issue Linking via IDOR
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-05T18:34:09.661Z

Reserved: 2026-10-02T14:59:11.776Z

Link: CVE-2026-104894

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-05T17:17:10.810

Modified: 2026-10-05T17:17:10.930

Link: CVE-2026-104894

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T18:30:19Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key