CVE-2026-104964: Plane: Cross-Workspace Project Modification via Unscoped Project Lookup

Published Oct 5, 2026
·
Updated

Plane is an open-source project management tool. Prior to 1.4.0, Plane's project update endpoint authorizes the caller against the workspace slug in the request URL but loads the target project globally by UUID without binding it to that workspace. An administrator of one workspace can modify a project in another workspace when the victim project UUID is known. This violates tenant isolation and permits unauthorized cross-workspace changes to project metadata and configuration. This issue is fixed in 1.4.0.

Affected Software

1 affected component
Plane Plane<1.4.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Plane to a version that resolves this vulnerability.

    Fixed in 1.4.0

Event History

Oct 5, 2026
CVE Published
via MITRE·04:52 PM
Data Sourced
via MITRE·04:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An administrator of one Plane workspace can exploit it against a project in a different workspace. The attacker must know the UUID of the target project.

2

Are deployments running the default configuration affected?

The issue is in the project update endpoint's authorization and project lookup behavior, not an optional configuration described in the advisory. Any Plane deployment prior to 1.4.0 where a workspace administrator can access that endpoint may be affected.

3

What can an attacker change?

An attacker can make unauthorized cross-workspace changes to the target project's metadata and configuration. The provided information does not indicate disclosure of project data or service disruption.

4

What should teams do if they cannot patch immediately?

No workaround is provided in the advisory. Until upgrading to 1.4.0, restrict and closely review workspace administrator access, and monitor project metadata and configuration changes for unexpected cross-workspace modifications.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203