Open-Source Project Management Tool Vulnerability in Plane
CVE-2026-104966
8.7HIGH
What is CVE-2026-104966?
The Plane open-source project management tool contains a security flaw that allows authenticated users to access and modify estimates and comments across different workspaces. Specifically, the endpoints for estimates and issues do not verify that resource identifiers belong to the correct workspace, leading to potential unauthorized data manipulation. This inconsistency can enable users to exploit the system and access sensitive data that should be restricted. The issue has been addressed in version 1.4.0, and users are advised to upgrade to protect their data integrity.
Affected Version(s)
plane < 1.4.0
