Sceawere

Vulnerability Detail

CVE-2026-104965UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Plane Insecure IDOR Issue Relations

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
2h ago
Vendor
makeplane
Product
plane
Attack Type
CWE-639: Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Plane is an open-source project management tool. Prior to 1.4.0, the issue-relation endpoint accepts issue UUIDs in the request body without validating that they belong to the caller's workspace. An authenticated user can create relations linking their own issues to issues in any other workspace on the instance, leaking issue metadata through activity events. This issue is fixed in 1.4.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-10-05T17:17:12.103Z",
  "pubdate": "2026-10-05T17:17:12.103Z",
  "executiveSummary": "A Broken Access Control vulnerability, specifically an Insecure Direct Object Reference (IDOR), exists in the issue-relation endpoint of the Plane project management tool prior to version 1.4.0.\nThe vulnerability allows an authenticated attacker to perform unauthorized cross-workspace operations by manipulating issue UUIDs provided in the request body.\nBy failing to validate that the submitted issue UUIDs belong to the caller's authorized workspace, the application permits users to create relationships between their own issues and arbitrary issues in other workspaces.\nThis unauthorized link triggers activity events that leak sensitive issue metadata, including titles and identifiers, to unauthorized parties.\nThe impact includes unauthorized information disclosure across isolated workspaces, violating multi-tenancy boundaries and data confidentiality expectations within the instance.\nExploitation requires a valid authenticated session, but does not require administrative privileges, as the vulnerability resides within the standard issue relationship creation workflow.",
  "technicalDetails": "The vulnerability is rooted in a failure to perform server-side authorization checks on the identifiers passed to the issue-relation endpoint. In Plane versions prior to 1.4.0, the backend logic accepts UUIDs for related issues within the request payload without validating the workspace ownership of the referenced resources.\nThe attack flow proceeds as follows: An authenticated user initiates a request to the issue-relation creation endpoint. While the user is authorized to create a relation within their own workspace, the system logic fails to verify if the 'related_issue_id' or 'issue_id' belongs to an authorized workspace context.\nBy supplying a target issue UUID from an arbitrary, external workspace, the attacker forces the application to link the target issue to an issue owned by the attacker. Upon successful execution of this operation, the application triggers internal activity event logs or notifications associated with the issue relationship update.\nBecause the application broadcasts these activity events, the metadata associated with the target issue—such as the issue title, status, and associated project details—is leaked to the actor who initiated the link, as well as potentially other participants observing the attacker's project activity feed.\nThe component responsible for this flaw is the backend API logic handling issue-relation creation. The vulnerability persists because the object-level access control (OLAC) checks are scoped strictly to the current session's write permission rather than the object's membership within the authenticated user's workspace scope.\nThis flaw is present in all deployments of Plane version 1.3.x and earlier. The exposure is limited to authenticated users who have basic access to the instance, as the vulnerability does not allow for unauthorized access to the entire database, but rather permits the systematic enumeration and discovery of metadata through controlled link creation.\nPost-exploitation impact involves the degradation of organizational data isolation. Attackers can leverage this to map the structure of other projects or identify sensitive issue descriptions that were intended to be private to other teams or organizations using the same Plane instance."
}
CVE-2026-104965: Plane Insecure IDOR Issue Relations (MEDIUM Severity, CVSS: 5.4) | Sceawere