CVE-2026-104969: Plane: Cross-Tenant Cycle Issue Hijack via IDOR
Plane is an open-source project management tool. Prior to 1.4.0, the cycle-issues endpoint accepts issue UUIDs in the request body without validating that they belong to the caller's workspace. An authenticated user can add issues from any workspace to a cycle they control. If a victim issue is already assigned to a cycle, the operation removes it from the victim's cycle, causing a destructive cross-tenant write. This issue is fixed in 1.4.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Planeto a version that resolves this vulnerability.Fixed in 1.4.0
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated Plane user can exploit it by controlling a cycle in their own workspace and submitting UUIDs for issues from another workspace. No user interaction is required.
What is the impact on affected workspaces?
An attacker can add a victim workspace's issue to a cycle they control. If that issue was already assigned to a cycle, the request removes it from the victim's existing cycle, resulting in an unauthorized destructive cross-tenant write.
Which versions are affected, and what is the remediation?
Plane versions prior to 1.4.0 are affected. Upgrade to Plane 1.4.0, which fixes the missing workspace ownership validation.