Cross-Workspace Vulnerability in Plane Project Management Tool by MakePlane
CVE-2026-104964

6.8MEDIUM

Key Information:

Vendor

Makeplane

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-104964?

The Plane project management tool, prior to version 1.4.0, has a cross-workspace vulnerability that undermines tenant isolation. This issue arises due to the project update endpoint's flawed authorization mechanism, which permits an administrator from one workspace to modify projects in another workspace if they know the targeted project's UUID. This significant oversight could lead to unauthorized alterations of project metadata and configuration, exposing users to risks and potential data breaches. The vulnerability was addressed in version 1.4.0, which rectifies this critical issue.

Affected Version(s)

plane < 1.4.0

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.