Open-Source Project Management Tool Vulnerability in Plane
CVE-2026-104966

8.7HIGH

Key Information:

Vendor

Makeplane

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-104966?

The Plane open-source project management tool contains a security flaw that allows authenticated users to access and modify estimates and comments across different workspaces. Specifically, the endpoints for estimates and issues do not verify that resource identifiers belong to the correct workspace, leading to potential unauthorized data manipulation. This inconsistency can enable users to exploit the system and access sensitive data that should be restricted. The issue has been addressed in version 1.4.0, and users are advised to upgrade to protect their data integrity.

Affected Version(s)

plane < 1.4.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.