Sceawere

Vulnerability Detail

CVE-2026-104967UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Plane Insecure Direct Object Reference

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
2h ago
Vendor
makeplane
Product
plane
Attack Type
CWE-639: Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Plane is an open-source project management tool. Prior to 1.4.0, BulkDeleteIssuesEndpoint and SubIssuesEndpoint in apps/api/plane/app/views/issue/ accept body- or URL-supplied issue IDs and operate on them without checking that the IDs belong to the caller's workspace and project. The permission decorator on each endpoint validates only that the caller is a member or administrator of the workspace and project named in the URL. BulkDeleteIssuesEndpoint can destroy CycleIssue and ModuleIssue associations belonging to foreign issues. SubIssuesEndpoint can re-parent foreign issues under an attacker-selected issue and return the foreign issues' metadata. This issue is fixed in 1.4.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-10-05T17:17:12.453Z",
  "pubdate": "2026-10-05T17:17:12.453Z",
  "executiveSummary": "Plane, an open-source project management platform, contains an Insecure Direct Object Reference (IDOR) vulnerability in its issue management API endpoints, specifically BulkDeleteIssuesEndpoint and SubIssuesEndpoint.\nThe vulnerability arises due to insufficient authorization checks where the application validates user workspace membership but fails to verify that the target issue IDs belong to the specified workspace or project.\nThis flaw allows an authenticated user with valid workspace access to perform unauthorized actions on issues residing in external workspaces or projects to which they should not have access.\nThe primary impact includes unauthorized data manipulation, including the deletion of cross-project issue associations (CycleIssue and ModuleIssue) and the unauthorized re-parenting of foreign issues, leading to potential data integrity loss, information disclosure, and disruption of project tracking workflows.\nThe vulnerability affects all versions of Plane prior to 1.4.0. Exploitation requires the attacker to have at least low-level member or administrative access to the platform, from which they can manipulate request payloads to reference unauthorized issue identifiers.",
  "technicalDetails": "The root cause of this vulnerability is a failure in the object-level authorization logic within the apps/api/plane/app/views/issue/ directory. While the implemented permission decorators successfully verify that a user is a legitimate member or administrator of a workspace, they do not enforce boundary constraints on the issue identifiers passed via request bodies or URL parameters.\nIn the context of the BulkDeleteIssuesEndpoint, the application processes deletion requests without validating the ownership or project scope of the provided issue IDs. Consequently, an attacker can supply the IDs of issues belonging to foreign workspaces. When executed, the system proceeds to destroy associations such as CycleIssue and ModuleIssue for these foreign entities. This effectively allows an attacker to corrupt the project structure and tracking associations of any project within the instance, regardless of their authorization status to the specific target project.\nThe SubIssuesEndpoint exhibits a similar architectural flaw, allowing attackers to re-parent foreign issues under a target issue controlled by the attacker. By manipulating the issue ID parameters, an attacker can modify the hierarchical relationship of issues that are cryptographically or logically isolated from their current workspace. Furthermore, the endpoint returns the metadata of these re-parented issues, facilitating an information disclosure vector where restricted issue details are leaked to an unauthorized caller.\nThe attack flow proceeds as follows: First, the attacker identifies valid issue IDs from foreign projects, potentially through enumeration or existing API responses. Second, the attacker constructs a malicious HTTP request targeting the SubIssuesEndpoint or BulkDeleteIssuesEndpoint. The request includes the attacker-controlled workspace context in the URL, satisfying the initial permission decorator check. Finally, the payload contains the unauthorized foreign issue IDs. The backend logic, bypassing the necessary object-level lookup and cross-reference check, executes the operation (re-parenting or deletion) against the unauthorized resources. This flaw persists across all versions prior to 1.4.0, representing a significant failure in multitenancy isolation and secure API design."
}
CVE-2026-104967: Plane Insecure Direct Object Reference (MEDIUM Severity, CVSS: 5.4) | Sceawere