CVE-2026-104964: Plane: Cross-Workspace Project Modification via Unscoped Project Lookup
Plane is an open-source project management tool. Prior to 1.4.0, Plane's project update endpoint authorizes the caller against the workspace slug in the request URL but loads the target project globally by UUID without binding it to that workspace. An administrator of one workspace can modify a project in another workspace when the victim project UUID is known. This violates tenant isolation and permits unauthorized cross-workspace changes to project metadata and configuration. This issue is fixed in 1.4.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Planeto a version that resolves this vulnerability.Fixed in 1.4.0
Event History
Frequently Asked Questions
Who can exploit this issue?
An administrator of one Plane workspace can exploit it against a project in a different workspace. The attacker must know the UUID of the target project.
Are deployments running the default configuration affected?
The issue is in the project update endpoint's authorization and project lookup behavior, not an optional configuration described in the advisory. Any Plane deployment prior to 1.4.0 where a workspace administrator can access that endpoint may be affected.
What can an attacker change?
An attacker can make unauthorized cross-workspace changes to the target project's metadata and configuration. The provided information does not indicate disclosure of project data or service disruption.
What should teams do if they cannot patch immediately?
No workaround is provided in the advisory. Until upgrading to 1.4.0, restrict and closely review workspace administrator access, and monitor project metadata and configuration changes for unexpected cross-workspace modifications.