PT-2026-106031 · Plane · Plane

·

CVE-2026-104963

·

Published

2026-10-05

·

Updated

2026-10-05

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Plane versions prior to 1.4.0
Description An authentication bypass allows any authenticated workspace member, including guests with limited access, to retrieve records from every project within a workspace. This occurs because the system fails to verify if the requester belongs to the specific project being accessed. An attacker can enumerate names, descriptions, sprint dates, issue counts, progress snapshots, external integration IDs, linked URLs, and member lists for cycles and modules in private projects via the following endpoints:
  • '/api/workspaces/{slug}/cycles/' through WorkspaceCyclesEndpoint
  • '/api/workspaces/{slug}/modules/' through WorkspaceModulesEndpoint
Recommendations Update to version 1.4.0.

Exploit

Fix

Incorrect Authorization

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-104963
GHSA-WCC5-QGFR-8G9C

Affected Products

Plane