Sceawere
Vulnerability Detail
CVE-2026-104894UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Plane Insecure Direct Object Reference
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 2h ago
- Vendor
- makeplane
- Product
- plane
- Attack Type
- CWE-639: Authorization Bypass Through User-Controlled Key
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Plane is an open-source project management tool. Prior to 1.4.0, the modules endpoint accepts issue UUIDs in the URL path without validating that they belong to the caller's workspace. An authenticated user can link issues from any workspace to modules in their own workspace. This issue is fixed in 1.4.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-05T17:17:10.810Z",
"pubdate": "2026-10-05T17:17:10.810Z",
"executiveSummary": "Plane, an open-source project management tool, contains an Insecure Direct Object Reference (IDOR) vulnerability in its modules endpoint prior to version 1.4.0.\nThe vulnerability allows an authenticated attacker to perform unauthorized cross-workspace operations by linking issue UUIDs from external workspaces to modules within their own controlled environment.\nThis flaw stems from a lack of server-side authorization checks when validating input parameters during the module update or association process.\nThe impact includes potential data exposure, unauthorized modification of issue metadata, and breach of logical workspace isolation boundaries.\nSuccessful exploitation requires an authenticated user account and knowledge of valid issue UUIDs, which may be discovered through enumeration or side-channel information disclosure.\nThe vulnerability represents a significant security risk for multi-tenant deployments where strict data segregation is required between different organizational workspaces.\nThis issue is fully addressed in the 1.4.0 release, which implements proper access control validation for workspace-scoped resources.",
"technicalDetails": "The vulnerability is classified as an Insecure Direct Object Reference (IDOR), located within the modules endpoint responsible for managing the relationship between issues and modules.\nThe root cause is a failure in the application's backend logic to implement rigorous authorization checks on incoming issue UUIDs provided in the URL path. Specifically, the API fails to verify the workspace ownership of the referenced issue before establishing a link to a module in the caller's workspace.\nIn a secure implementation, the system should validate that the provided issue UUID belongs to a workspace to which the authenticated user has authorized access. In Plane prior to 1.4.0, the backend assumes that if a user is authenticated, they have sufficient permissions to modify any issue provided by the client, regardless of the issue's original workspace association.\nThe attack flow follows these steps: 1. An attacker authenticates to their own legitimate Plane workspace. 2. The attacker identifies or enumerates a target issue UUID residing in a different, unauthorized workspace. 3. The attacker submits a request to the modules endpoint with the target issue UUID in the URL path, effectively instructing the backend to link the foreign issue to a module within the attacker's workspace. 4. The server processes the request without cross-referencing the issue's parent workspace against the current user's security context. 5. The application state is updated, successfully bridging the data between distinct logical workspaces.\nThis vulnerability is reachable over the network via the standard web interface or API interaction. Because the flaw exists at the API/endpoint level, it is easily scriptable, allowing for automated mass association of unauthorized issues if UUIDs can be enumerated.\nPost-exploitation, the attacker may effectively bring sensitive data from other workspaces into their own view, potentially leaking internal task details, titles, or descriptions that were intended to remain private. Furthermore, this manipulation disrupts the integrity of the project management data, as issues are moved or referenced against organizational policies or access control lists.\nAffected versions include all releases prior to 1.4.0. The remediation involves updating to 1.4.0 or later, where explicit authorization logic has been introduced to validate the workspace identity of all resources before performing object manipulation."
}