Cross-Tenant IDOR in Open-Source Project Management Tool by MakePlane
CVE-2026-105629
7.1HIGH
What is CVE-2026-105629?
The vulnerability in Plane, an open-source project management tool, allows an administrator or member of one workspace to exploit a flaw in the BulkEstimatePointEndpoint.destroy functionality. By utilizing a bare primary-key lookup without proper scoping to workspace, project, or estimate, an attacker can permanently delete an estimate point belonging to a different workspace by providing the target UUID through a URL under their own workspace. This oversight leads to a severe cross-tenant IDOR vulnerability. The issue has been addressed in version 1.4.0.
Affected Version(s)
plane < 1.4.0
