PT-2026-106032 · Plane · Plane
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Plane versions prior to 1.4.0
Description
An issue exists in the project update endpoint where the system authorizes the caller based on the workspace slug in the request URL but loads the target project globally by UUID without verifying its association with that workspace. This flaw allows an administrator of one workspace to modify a project in a different workspace if the target project UUID is known, resulting in a breach of tenant isolation and unauthorized changes to project metadata and configuration.
Recommendations
Update to version 1.4.0.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Plane