PT-2026-106034 · Plane · Plane

·

CVE-2026-104966

·

Published

2026-10-05

·

Updated

2026-10-05

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Plane versions prior to 1.4.0
Description Two endpoint families fail to verify that nested resource identifiers belong to the workspace and project specified in the URL. An authenticated user can read or modify estimates from another workspace via the PATCH '/api/workspaces/{slug}/projects/{project id}/estimates/{estimate id}/' endpoint, or inject comments into an issue from another workspace via the POST '/api/workspaces/{slug}/projects/{project id}/issues/{issue id}/comments/' endpoint. While the ProjectEntityPermission function verifies membership in the workspace and project from the URL, the estimate id and issue id variables are fetched by primary key without confirming the same scope.
Recommendations Update to version 1.4.0.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-104966
GHSA-933R-RXG8-F3H2

Affected Products

Plane