Sceawere

Vulnerability Detail

CVE-2026-105629UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Plane IDOR Estimate Point Deletion

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
makeplane
Product
plane
Attack Type
CWE-639: Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Attack Complexity
LOW

Narrative and Response

Description

Plane is an open-source project management tool. Prior to 1.4.0, BulkEstimatePointEndpoint.destroy resolves an estimate point through a bare primary-key lookup without workspace, project, or estimate scoping. An administrator or member of one workspace can permanently delete an estimate point belonging to another workspace by supplying the target UUID in a URL under the attacker's own workspace. This creates a destructive cross-tenant IDOR. This issue is fixed in 1.4.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-05T18:17:36.087Z",
  "pubdate": "2026-10-05T18:17:36.087Z",
  "executiveSummary": "This vulnerability is an Insecure Direct Object Reference (IDOR) affecting Plane versions prior to 1.4.0.\nThe flaw resides within the BulkEstimatePointEndpoint.destroy function, which performs object deletion based solely on a primary-key lookup without verifying the object's association with the current workspace or project.\nThis allows an authenticated user, such as an administrator or member within a legitimate workspace, to trigger the permanent deletion of arbitrary estimate points located in entirely different, unauthorized workspaces.\nThe vulnerability effectively bypasses multi-tenancy isolation mechanisms inherent in the application's architecture.\nThe impact is significant, as it enables malicious actors to perform cross-tenant data destruction, compromising the integrity and availability of project management data across the platform.\nExploitation requires only valid authentication within the platform; no specific elevated privileges beyond workspace membership are necessary to target external objects.\nThe risk is critical due to the ease of exploitation and the potential for large-scale, unauthorized data removal across the hosted environment.",
  "technicalDetails": "The root cause of this vulnerability is improper access control validation within the BulkEstimatePointEndpoint.destroy function in Plane prior to version 1.4.0.\nThe application relies on a bare primary-key lookup to identify and remove estimate point objects. The backend logic fails to implement mandatory scoping checks to ensure the requested object UUID belongs to the authenticated user's current workspace, project, or relevant organizational boundary.\nIn a secure implementation, the object lookup should be constrained by the application's authorization layer, typically by joining the query with the workspace ID or project ID derived from the user's session context.\nThe attack flow begins when an attacker identifies the UUID of a target estimate point belonging to an external workspace. Due to the lack of server-side validation, the attacker can submit a crafted HTTP DELETE request containing the target UUID to the BulkEstimatePointEndpoint.destroy interface within their own workspace.\nBecause the application logic does not verify that the target object is scoped to the user's workspace, the database layer executes a delete operation on the specified primary key regardless of its origin.\nThis behavior results in a cross-tenant IDOR, where the authorization context is limited to the endpoint access itself rather than the integrity of the object reference.\nThis vulnerability is reproducible by any authenticated user who has the ability to interact with the API. The endpoint does not perform an existence or ownership check against the organizational hierarchy before invoking the deletion command.\nPost-exploitation impact involves the permanent removal of estimate point data from other tenants' projects, leading to data loss and potential disruption of project tracking metrics and administrative operations for the victims.\nAffected versions are all Plane releases prior to 1.4.0. The remediation provided in 1.4.0 addresses this by ensuring that all database queries performed by the destruction endpoint enforce proper scoping through workspace and project ownership validation."
}
CVE-2026-105629: Plane IDOR Estimate Point Deletion (HIGH Severity, CVSS: 7.1) | Sceawere