Sceawere

Vulnerability Detail

CVE-2026-104975UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Plane Spaces Asset IDOR Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
makeplane
Product
plane
Attack Type
CWE-639: Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Plane is an open-source project management tool. Prior to 1.4.0, Plane's dashboard asset endpoints in plane/app/views/asset/v2.py were remediated for two cross-tenant asset IDORs, CVE-2026-27705 and CVE-2026-46558. Those fixes added a membership check and project_id and workspace__slug scoping to the asset endpoints in that file. The Spaces app in plane/space/views/asset.py serves related public-board operations under /api/public/ but was not remediated. Its EntityAssetEndpoint and AssetRestoreEndpoint resolve a DeployBoard from a public anchor and then read or modify FileAsset rows scoped only to the board's workspace, without a membership check or project_id constraint. An attacker can therefore read, overwrite, or restore assets across projects and workspaces. This issue is fixed in 1.4.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-05T18:17:32.747Z",
  "pubdate": "2026-10-05T18:17:32.747Z",
  "executiveSummary": "A cross-tenant Insecure Direct Object Reference (IDOR) vulnerability exists in the Spaces application of the Plane project management tool, specifically within the public-facing asset management endpoints. The vulnerability stems from insufficient authorization checks when handling file assets associated with public boards.\nAlthough Plane previously remediated similar flaws in the core dashboard asset endpoints (CVE-2026-27705 and CVE-2026-46558), the Spaces module in plane/space/views/asset.py remained unpatched. This oversight allows an attacker to interact with assets across different workspaces and projects without legitimate authorization.\nAn unauthenticated or authenticated attacker can leverage these endpoints to perform unauthorized read, overwrite, or restoration operations on sensitive files. The risk is significant, as it permits unauthorized access to proprietary data or the potential for data corruption and integrity loss across the entire platform. The vulnerability is resolved in version 1.4.0.",
  "technicalDetails": "The vulnerability resides within the EntityAssetEndpoint and AssetRestoreEndpoint functions located in plane/space/views/asset.py. The application provides public-facing operations for project boards under the /api/public/ URI path. The underlying logic resolves a DeployBoard based on a public anchor but fails to implement robust access controls for the associated FileAsset rows.\nSpecifically, the affected endpoints perform object lookups scoped only to the workspace identified by the board, completely neglecting mandatory membership verification and project_id constraints. While the core dashboard asset endpoints were previously hardened to prevent cross-tenant access via CVE-2026-27705 and CVE-2026-46558, the Spaces app lacks equivalent logic. The current implementation assumes that identifying the workspace via the board is sufficient, ignoring that a single workspace may contain multiple isolated projects and numerous private assets.\nThe attack flow proceeds as follows: 1) An attacker identifies a valid public anchor to resolve a target DeployBoard. 2) The attacker crafts requests to the vulnerable /api/public/ endpoints, manipulating asset identifiers. 3) Because the backend logic omits a check to verify if the user possesses membership in the specific project, or if the asset belongs to the authorized project_id, the application proceeds to process the request. 4) The attacker successfully performs CRUD operations—reading, overwriting, or restoring—against assets that belong to projects or workspaces outside of their intended scope.\nThis vulnerability is particularly severe because it bypasses the multi-tenancy logical isolation provided by the platform. Since these endpoints serve public-board operations, the barrier to exploitation is low; an attacker does not necessarily require high-privilege credentials to traverse the asset database. The absence of strict scoping at the controller level effectively permits horizontal privilege escalation, where an attacker can access sensitive file assets belonging to any user or project within the same workspace, and potentially across workspace boundaries depending on underlying database queries.\nThe impact includes full unauthorized access to sensitive project documentation, code snippets, or media stored as FileAsset entities, and the ability to corrupt or manipulate these assets, leading to a loss of data integrity across the Plane ecosystem."
}
CVE-2026-104975: Plane Spaces Asset IDOR Vulnerability (HIGH Severity, CVSS: 7.1) | Sceawere