Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Atomics-Hub

#50246of 57,632
5.4Total CVSS
Vulnerabilities · 1
PT-2026-106035
5.4
2026-10-05
Plane · Plane · CVE-2026-104967
**Name of the Vulnerable Software and Affected Versions** Plane versions prior to 1.4.0 **Description** An authorization bypass exists in the `BulkDeleteIssuesEndpoint` and `SubIssuesEndpoint` located in `apps/api/plane/app/views/issue/`. These endpoints process issue IDs provided via the request body or URL without verifying if the IDs belong to the caller's workspace and project. While the permission decorator confirms the caller is a member or administrator of the workspace and project specified in the URL, it fails to validate the individual issue IDs. Consequently, `BulkDeleteIssuesEndpoint` can be used to destroy `CycleIssue` and `ModuleIssue` associations of foreign issues, and `SubIssuesEndpoint` can be used to re-parent foreign issues under an issue selected by an attacker and retrieve their metadata. **Recommendations** Update to version 1.4.0.