Plane · Plane · CVE-2026-104967
**Name of the Vulnerable Software and Affected Versions**
Plane versions prior to 1.4.0
**Description**
An authorization bypass exists in the `BulkDeleteIssuesEndpoint` and `SubIssuesEndpoint` located in `apps/api/plane/app/views/issue/`. These endpoints process issue IDs provided via the request body or URL without verifying if the IDs belong to the caller's workspace and project. While the permission decorator confirms the caller is a member or administrator of the workspace and project specified in the URL, it fails to validate the individual issue IDs. Consequently, `BulkDeleteIssuesEndpoint` can be used to destroy `CycleIssue` and `ModuleIssue` associations of foreign issues, and `SubIssuesEndpoint` can be used to re-parent foreign issues under an issue selected by an attacker and retrieve their metadata.
**Recommendations**
Update to version 1.4.0.