Impact
Plane is an open‑source project management tool that allowed administrators in one workspace to modify projects in another workspace by supplying the target project’s UUID. The vulnerability bypasses intended workspace scoping, enabling unauthorized cross‑tenant changes to project metadata and configuration, a flaw described as a lack of tenant isolation (CWE‑639).
Affected Systems
All installations of Plane using a version prior to 1.4.0 are affected. Administrators of any workspace could exploit the flaw to alter projects in other workspaces when the UUID of the target project is known.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity. Attackers must possess administrator privileges in one workspace and know the UUID of a project in another workspace. The lookup is unscoped, so the exploit works regardless of the workspace specified in the request URL. The vulnerability is not listed in CISA’s KEV catalog, and no EPSS data is available, suggesting limited public exploitation. However, installations with broadly scoped administrative rights remain at risk for unauthorized cross‑workspace data modification.
OpenCVE Enrichment