Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Mguptahub

#22659of 57,632
12.2Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-106029
5.4
2026-10-05
Plane · Plane · CVE-2026-104961
**Name of the Vulnerable Software and Affected Versions** Plane versions prior to 1.4.0 **Description** WorkspaceOwnerPermission does not verify if the `is active` variable is set to True when validating if a user is a workspace owner. This allows a deactivated user to maintain authorization and retain owner-level access to the workspace. **Recommendations** Update to version 1.4.0.
PT-2026-106032
6.8
2026-10-05
Plane · Plane · CVE-2026-104964
**Name of the Vulnerable Software and Affected Versions** Plane versions prior to 1.4.0 **Description** An issue exists in the project update endpoint where the system authorizes the caller based on the workspace slug in the request URL but loads the target project globally by UUID without verifying its association with that workspace. This flaw allows an administrator of one workspace to modify a project in a different workspace if the target project UUID is known, resulting in a breach of tenant isolation and unauthorized changes to project metadata and configuration. **Recommendations** Update to version 1.4.0.