Impact
The vulnerability is an insecure direct object reference that permits a user with membership or administrator rights in one workspace to delete estimate points belonging to another workspace without permission checks. The flaw results from the BulkEstimatePointEndpoint.destroy action resolving an estimate point through a bare primary‑key lookup, ignoring any workspace, project, or estimate scoping. Successful exploitation leads to unintentional or malicious removal of project data, thereby violating integrity and potentially disrupting team collaboration.
Affected Systems
Plane, the open‑source project management platform maintained by Makeplane, is affected. All releases prior to v1.4.0 contain the flaw; starting with release v1.4.0 the issue is fixed. Organizations running any 1.x series below 1.4.0 are at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity level, and although the EPSS metric is not available, the lack of a KEV listing suggests the vulnerability has not yet been widely exploited in the wild. Attackers only need to be authenticated members of a workspace to target the vulnerable endpoint; no additional privileges are required beyond normal workspace access. Consequently the likelihood of exploitation is moderate, and a determined adversary could leverage this IDOR to delete critical project artifacts across tenants.
OpenCVE Enrichment