Plane · Plane · CVE-2026-104964
**Name of the Vulnerable Software and Affected Versions**
Plane versions prior to 1.4.0
**Description**
An issue exists in the project update endpoint where the system authorizes the caller based on the workspace slug in the request URL but loads the target project globally by UUID without verifying its association with that workspace. This flaw allows an administrator of one workspace to modify a project in a different workspace if the target project UUID is known, resulting in a breach of tenant isolation and unauthorized changes to project metadata and configuration.
**Recommendations**
Update to version 1.4.0.