PT-2026-106032 · Plane · Plane

·

CVE-2026-104964

·

Published

2026-10-05

·

Updated

2026-10-05

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Plane versions prior to 1.4.0
Description An issue exists in the project update endpoint where the system authorizes the caller based on the workspace slug in the request URL but loads the target project globally by UUID without verifying its association with that workspace. This flaw allows an administrator of one workspace to modify a project in a different workspace if the target project UUID is known, resulting in a breach of tenant isolation and unauthorized changes to project metadata and configuration.
Recommendations Update to version 1.4.0.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-104964
GHSA-PP22-3GHF-949Q

Affected Products

Plane