CVE-2026-104975: CWE-639: Authorization Bypass Through User-Controlled Key in makeplane plane
Description
Plane is an open-source project management tool. Prior to 1.4.0, Plane's dashboard asset endpoints in plane/app/views/asset/v2.py were remediated for two cross-tenant asset IDORs, CVE-2026-27705 and CVE-2026-46558. Those fixes added a membership check and project_id and workspace__slug scoping to the asset endpoints in that file. The Spaces app in plane/space/views/asset.py serves related public-board operations under /api/public/ but was not remediated. Its EntityAssetEndpoint and AssetRestoreEndpoint resolve a DeployBoard from a public anchor and then read or modify FileAsset rows scoped only to the board's workspace, without a membership check or project_id constraint. An attacker can therefore read, overwrite, or restore assets across projects and workspaces. This issue is fixed in 1.4.0.
CVSS v3.1
Score 7.1high
Affected software
makeplane
plane
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-104975 is an authorization bypass vulnerability in the Plane project management tool's Spaces app, specifically in the EntityAssetEndpoint and AssetRestoreEndpoint under /api/public/. These endpoints resolve a DeployBoard from a public anchor and access FileAsset rows scoped only to the board's workspace but lack membership checks and project_id constraints. This flaw enables attackers to access and modify assets across projects and workspaces without proper authorization. The vulnerability was addressed in Plane version 1.4.0 by adding appropriate membership and project scoping checks.
Potential Impact
An attacker with at least limited privileges can exploit this vulnerability to read, overwrite, or restore assets belonging to other projects and workspaces, potentially leading to unauthorized data disclosure and integrity violations. The CVSS v3.1 score is 7.1 (high severity), reflecting network attack vector, low attack complexity, required privileges, no user interaction, and high confidentiality impact with limited integrity impact.
Mitigation Recommendations
Upgrade Plane to version 1.4.0 or later, where this authorization bypass vulnerability has been fixed by adding membership checks and project scoping to the affected endpoints. No other mitigations are indicated. Patch status is confirmed fixed in 1.4.0.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-10-02T18:16:13.629Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac3e69f2cdf04f65628b493
Added to database: 10/05/2026, 18:04:15 UTC
Last enriched: 10/05/2026, 18:18:15 UTC
Last updated: 10/05/2026, 18:56:34 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.