Description
Plane is an open-source project management tool. Prior to 1.4.0, two endpoint families fail to verify that nested resource identifiers belong to the workspace and project named in the URL. An authenticated user can read or modify estimates from another workspace through PATCH /api/workspaces/{slug}/projects/{project_id}/estimates/{estimate_id}/, and can inject comments into an issue from another workspace through POST /api/workspaces/{slug}/projects/{project_id}/issues/{issue_id}/comments/. ProjectEntityPermission verifies membership in the workspace and project from the URL, but estimate_id and issue_id are fetched by primary key without confirming the same scope. The list, retrieve, and destroy handlers correctly scope their queries, demonstrating the inconsistency. This issue is fixed in 1.4.0.
Published: 2026-10-05
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Privilege escalation and data tampering via cross‑workspace IDOR
Action: Immediate Patch
AI Analysis

Impact

An authenticated user can exploit an IDOR flaw in Plane’s estimate and comment endpoints, reading or updating estimates and injecting comments that belong to another workspace. The flaw stems from the API not verifying that the estimate or issue identifiers in the request path match the workspace and project specified in the URL. According to the CVE description, ProjectEntityPermission checks membership in the workspace and project from the URL, but the database look‑ups for estimate_id and issue_id ignore this context, permitting unauthorized access. This leads to confidentiality breaches, integrity violations, and untrusted input injection, as the attacker can create arbitrary comments in any workspace where the attacker holds a valid account. The identified weakness is CWE‑639, a classic Insecure Direct Object Reference scenario.

Affected Systems

The vulnerability affects the open‑source project management tool Plane from makeplane. All releases prior to version 1.4.0 are susceptible, including 1.3.x and earlier. Users running these affected versions without an upgrade are exposed.

Risk and Exploitability

The CVSS score of 8.7 classifies the issue as High severity, indicating significant impact if exploited. The EPSS score is not available, but the absence of a KEV listing does not diminish risk; the vulnerability requires only an authenticated user and an accessible endpoint, making exploitation relatively straightforward in environments where users have cross‑workspace privileges. The attack vector is inferred to be internal, as the victim must be an authenticated user who has some level of access across multiple workspaces. Given the simplicity of the request paths and the lack of client‑side protection, the likelihood of exploitation in active deployments is non‑negligible.

Generated by OpenCVE AI on October 5, 2026 at 19:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Plane version 1.4.0 or later where the IDOR flaw is corrected.
  • Verify that the /estimates and /comments endpoints now enforce workspace and project scoping before re‑allowing external API access.
  • Review and tighten user permissions so that only authorized roles have the ability to access or modify estimates and comments across workspaces.

Generated by OpenCVE AI on October 5, 2026 at 19:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Makeplane
Makeplane plane
Vendors & Products Makeplane
Makeplane plane

Mon, 05 Oct 2026 17:00:00 +0000

Type Values Removed Values Added
Description Plane is an open-source project management tool. Prior to 1.4.0, two endpoint families fail to verify that nested resource identifiers belong to the workspace and project named in the URL. An authenticated user can read or modify estimates from another workspace through PATCH /api/workspaces/{slug}/projects/{project_id}/estimates/{estimate_id}/, and can inject comments into an issue from another workspace through POST /api/workspaces/{slug}/projects/{project_id}/issues/{issue_id}/comments/. ProjectEntityPermission verifies membership in the workspace and project from the URL, but estimate_id and issue_id are fetched by primary key without confirming the same scope. The list, retrieve, and destroy handlers correctly scope their queries, demonstrating the inconsistency. This issue is fixed in 1.4.0.
Title Plane: Cross-Workspace IDOR in Estimate and Comment Endpoints Allows Read, Modify, and Inject Across Workspaces
Weaknesses CWE-639
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-05T16:54:27.158Z

Reserved: 2026-10-02T18:16:13.629Z

Link: CVE-2026-104966

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-05T17:17:12.283

Modified: 2026-10-05T17:17:12.410

Link: CVE-2026-104966

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T19:15:10Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key