PT-2026-86398 · Plane · Plane

·

CVE-2026-86174

·

Published

2026-09-05

·

Updated

2026-09-05

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Plane versions prior to 1.4.3
Description Authenticated attackers can post comments to arbitrary issues across different workspaces. This occurs because the software fails to validate whether issues belong to the deploy board's project when using the public comment endpoint. The attack is executed by supplying a specific issue id parameter to the public deploy-board comment endpoint.
Recommendations Update to version 1.4.3 or later. Restrict access to the public deploy-board comment endpoint to minimize the risk of unauthorized comment posting.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86174

Affected Products

Plane