Sceawere

Vulnerability Detail

CVE-2026-104969UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Plane Insecure Cross-Workspace Issue Assignment

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
2h ago
Vendor
makeplane
Product
plane
Attack Type
CWE-639: Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Plane is an open-source project management tool. Prior to 1.4.0, the cycle-issues endpoint accepts issue UUIDs in the request body without validating that they belong to the caller's workspace. An authenticated user can add issues from any workspace to a cycle they control. If a victim issue is already assigned to a cycle, the operation removes it from the victim's cycle, causing a destructive cross-tenant write. This issue is fixed in 1.4.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-05T17:17:12.783Z",
  "pubdate": "2026-10-05T17:17:12.783Z",
  "executiveSummary": "The vulnerability is a Broken Object Level Authorization (BOLA) flaw identified in Plane versions prior to 1.4.0. It manifests within the cycle-issues endpoint, where the application fails to enforce tenant isolation during the issue assignment process. By providing arbitrary issue UUIDs in the request body, an authenticated user can manipulate cycles across distinct workspaces.\nThis vulnerability allows unauthorized cross-tenant data modification, leading to the integrity compromise of project management data belonging to other organizations. The attack is executable by any authenticated user without requiring escalated administrative privileges, provided they can identify target issue UUIDs. The risk is significant, as it enables malicious actors to disrupt operational workflows, remove issues from legitimate cycles, and perform destructive cross-tenant writes within a multi-tenant environment.",
  "technicalDetails": "The root cause of this vulnerability lies in an improper authorization check within the backend logic governing the cycle-issues endpoint. The API fails to perform a cross-reference validation between the submitted issue UUID and the workspace context of the authenticated user. In a secure multi-tenant architecture, the system should verify that both the target cycle and the specified issues belong to the same authorized workspace before committing changes to the database.\nThe exploitation method involves an authenticated attacker interacting with the cycle-issues assignment API. When a request is crafted to include a foreign issue UUID—an issue belonging to a different workspace—the application process accepts the input as valid because it relies solely on the user's authentication token rather than the authorization scope of the specific workspace. The endpoint logic effectively performs an 'add' operation regardless of whether the user possesses write permissions on the target resource.\nThe attack flow proceeds as follows: 1) The attacker authenticates to their own workspace and identifies the UUID of a target issue located in a victim's workspace. 2) The attacker sends a POST or PUT request to the vulnerable cycle-issues endpoint within their controlled workspace, injecting the victim's issue UUID into the request body. 3) The server-side code processes the request, updating the database records to associate the external issue with the attacker's cycle. 4) A destructive side effect occurs because the database schema or business logic enforces a single-cycle association for issues. By adding the victim's issue to an unauthorized cycle, the application automatically triggers a detachment of that issue from the original, legitimate cycle in the victim's workspace.\nThis vulnerability represents a significant failure in access control implementation, specifically regarding object-level authorization in a multi-tenant cloud application. Because the application logic does not validate the relationship between the session user, the workspace ID, and the object UUIDs provided in the payload, it creates an insecure direct object reference (IDOR) scenario. The post-exploitation impact includes unauthorized data migration, workflow disruption for the victim organization, and the potential for large-scale data manipulation across tenants."
}
CVE-2026-104969: Plane Insecure Cross-Workspace Issue Assignment (MEDIUM Severity, CVSS: 6.5) | Sceawere