Description
Plane is an open-source project management tool. Prior to 1.4.0, BulkEstimatePointEndpoint.destroy resolves an estimate point through a bare primary-key lookup without workspace, project, or estimate scoping. An administrator or member of one workspace can permanently delete an estimate point belonging to another workspace by supplying the target UUID in a URL under the attacker's own workspace. This creates a destructive cross-tenant IDOR. This issue is fixed in 1.4.0.
Published: 2026-10-05
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Cross‑tenant destructive IDOR leading to data loss
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an insecure direct object reference that permits a user with membership or administrator rights in one workspace to delete estimate points belonging to another workspace without permission checks. The flaw results from the BulkEstimatePointEndpoint.destroy action resolving an estimate point through a bare primary‑key lookup, ignoring any workspace, project, or estimate scoping. Successful exploitation leads to unintentional or malicious removal of project data, thereby violating integrity and potentially disrupting team collaboration.

Affected Systems

Plane, the open‑source project management platform maintained by Makeplane, is affected. All releases prior to v1.4.0 contain the flaw; starting with release v1.4.0 the issue is fixed. Organizations running any 1.x series below 1.4.0 are at risk.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity level, and although the EPSS metric is not available, the lack of a KEV listing suggests the vulnerability has not yet been widely exploited in the wild. Attackers only need to be authenticated members of a workspace to target the vulnerable endpoint; no additional privileges are required beyond normal workspace access. Consequently the likelihood of exploitation is moderate, and a determined adversary could leverage this IDOR to delete critical project artifacts across tenants.

Generated by OpenCVE AI on October 5, 2026 at 20:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Plane installation to version 1.4.0 or later, where the IDOR issue is resolved.
  • If an immediate upgrade is infeasible, restrict the BulkEstimatePointEndpoint.destroy action so that only workspace administrators or super‑users can invoke it; remove delete permissions for regular members.
  • Audit and enforce proper scoping for all API endpoints in the application to ensure that object identifiers are always validated against the user’s tenant context.

Generated by OpenCVE AI on October 5, 2026 at 20:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Makeplane
Makeplane plane
Vendors & Products Makeplane
Makeplane plane

Mon, 05 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Description Plane is an open-source project management tool. Prior to 1.4.0, BulkEstimatePointEndpoint.destroy resolves an estimate point through a bare primary-key lookup without workspace, project, or estimate scoping. An administrator or member of one workspace can permanently delete an estimate point belonging to another workspace by supplying the target UUID in a URL under the attacker's own workspace. This creates a destructive cross-tenant IDOR. This issue is fixed in 1.4.0.
Title Plane: Cross-Tenant Destructive IDOR: Estimate Point Deletion via Unscoped Primary Key Lookup
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-05T17:53:01.671Z

Reserved: 2026-10-05T16:40:39.611Z

Link: CVE-2026-105629

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-05T18:17:36.087

Modified: 2026-10-05T18:17:36.207

Link: CVE-2026-105629

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T20:15:16Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key