Information Disclosure in Plane Project Management Tool
CVE-2026-104963

4.3MEDIUM

Key Information:

Vendor

Makeplane

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-104963?

The Plane project management tool, before version 1.4.0, is susceptible to an information disclosure vulnerability. This flaw allows any authenticated member of a workspace, including those with guest access to a single project, to retrieve sensitive details about private projects through specific API endpoints without proper access controls. The affected API endpoints include GET /api/workspaces/{slug}/cycles/ and GET /api/workspaces/{slug}/modules/, which expose critical data such as project names, descriptions, sprint dates, issue counts, progress snapshots, external integration IDs, and member lists. The inconsistency in access control checks between these endpoints and their counterparts poses a significant risk to user privacy and project security. This issue has been addressed in version 1.4.0.

Affected Version(s)

plane < 1.4.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.