Cross-Workspace Vulnerability in Plane Project Management Tool by MakePlane
CVE-2026-104964
6.8MEDIUM
What is CVE-2026-104964?
The Plane project management tool, prior to version 1.4.0, has a cross-workspace vulnerability that undermines tenant isolation. This issue arises due to the project update endpoint's flawed authorization mechanism, which permits an administrator from one workspace to modify projects in another workspace if they know the targeted project's UUID. This significant oversight could lead to unauthorized alterations of project metadata and configuration, exposing users to risks and potential data breaches. The vulnerability was addressed in version 1.4.0, which rectifies this critical issue.
Affected Version(s)
plane < 1.4.0
