Description
Plane is an open-source project management tool. Prior to 1.4.0, the cycle-issues endpoint accepts issue UUIDs in the request body without validating that they belong to the caller's workspace. An authenticated user can add issues from any workspace to a cycle they control. If a victim issue is already assigned to a cycle, the operation removes it from the victim's cycle, causing a destructive cross-tenant write. This issue is fixed in 1.4.0.
Published: 2026-10-05
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Destructive Cross‑Tenant Modification
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an Insecure Direct Object Reference in Plane’s cycle‑issues endpoint. An authenticated user can submit an issue UUID without the system verifying that the issue belongs to the caller’s workspace, enabling the user to add an issue from any workspace to a cycle they manage. If the target issue is already part of another cycle, the operation removes it from that cycle. This results in a destructive cross‑tenant modification, undermining Integrity for the victim workspace and potentially disrupting project planning.

Affected Systems

The flaw affects all releases of Plane before version 1.4.0. Users running makeplane:plane on older versions should verify their installation version, as the issue has been fixed in the 1.4.0 release.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, and the exploit probability is unknown due to missing EPSS data. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector requires the attacker to be an authenticated user who has access to the target workspace’s cycle and the ability to submit requests to the API. Since no mitigations are available outside of upgrading, the risk is primarily exploitable by internal actors with sufficient privileges.

Generated by OpenCVE AI on October 5, 2026 at 18:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Plane to version 1.4.0 or later to apply the patch that enforces workspace ownership checks on the cycle‑issues endpoint.
  • Remove or revoke any existing cycles that link issues from other workspaces to prevent accidental cross‑tenant modifications; verify that no issues are assigned to cycles outside their originating workspace.
  • If an immediate upgrade is not possible, temporarily block the /cycle‑issues API or restrict user roles so that only users with sole workspace ownership can add issues to cycles, effectively preventing cross‑tenant assignments until the fix is deployed.

Generated by OpenCVE AI on October 5, 2026 at 18:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Makeplane
Makeplane plane
Vendors & Products Makeplane
Makeplane plane

Mon, 05 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 17:15:00 +0000

Type Values Removed Values Added
Description Plane is an open-source project management tool. Prior to 1.4.0, the cycle-issues endpoint accepts issue UUIDs in the request body without validating that they belong to the caller's workspace. An authenticated user can add issues from any workspace to a cycle they control. If a victim issue is already assigned to a cycle, the operation removes it from the victim's cycle, causing a destructive cross-tenant write. This issue is fixed in 1.4.0.
Title Plane: Cross-Tenant Cycle Issue Hijack via IDOR
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-05T17:48:30.635Z

Reserved: 2026-10-02T18:16:13.629Z

Link: CVE-2026-104969

cve-icon Vulnrichment

Updated: 2026-10-05T17:48:17.128Z

cve-icon NVD

Status : Deferred

Published: 2026-10-05T17:17:12.783

Modified: 2026-10-05T18:17:32.003

Link: CVE-2026-104969

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T18:45:19Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key