CVE-2026-104966 Overview
Plane is an open-source project management tool. CVE-2026-104966 is an Insecure Direct Object Reference [CWE-639] vulnerability affecting Plane versions prior to 1.4.0. Two API endpoint families fail to verify that nested resource identifiers belong to the workspace and project named in the URL. An authenticated user can read or modify estimates belonging to another workspace, and inject comments into issues owned by another workspace. The flaw was fixed in Plane 1.4.0.
Critical Impact
Authenticated users can cross workspace and project boundaries to tamper with estimates and inject comments into issues in tenants they do not belong to.
Affected Products
- Plane (makeplane/plane) versions prior to 1.4.0
- Self-hosted Plane deployments exposing the /api/workspaces/{slug}/projects/{project_id}/estimates/ endpoint
- Self-hosted Plane deployments exposing the /api/workspaces/{slug}/projects/{project_id}/issues/{issue_id}/comments/ endpoint
Discovery Timeline
- 2026-10-05 - CVE-2026-104966 published to NVD
- 2026-10-06 - Last updated in NVD database
Technical Details for CVE-2026-104966
Vulnerability Analysis
The vulnerability stems from inconsistent scoping of nested resources in Plane's REST API. The ProjectEntityPermission class verifies that the authenticated user belongs to the workspace and project named in the URL path. However, the create, update, and comment handlers then look up estimate_id and issue_id by primary key without validating that those identifiers resolve to the same workspace and project.
A user who legitimately belongs to Workspace A can craft a request against /api/workspaces/{slug_A}/projects/{project_A}/estimates/{estimate_id_B}/ using an estimate_id that actually belongs to Workspace B. Permission checks pass against Workspace A, but the ORM operates on the Workspace B object. The list, retrieve, and destroy handlers correctly scope their queries, which exposes the inconsistency.
Root Cause
The root cause is missing authorization at the object level [CWE-639]. The permission layer validates the URL path components but the handler resolves nested resources through unscoped primary key lookups, allowing cross-tenant object access.
Attack Vector
An authenticated Plane user issues a PATCH /api/workspaces/{slug}/projects/{project_id}/estimates/{estimate_id}/ request where estimate_id is enumerated or guessed from another workspace. The same technique works against POST /api/workspaces/{slug}/projects/{project_id}/issues/{issue_id}/comments/ to inject comments into foreign issues. No elevated privileges are required beyond workspace membership.
{"error": "Key and value are required"},
status=status.HTTP_400_BAD_REQUEST,
)
+ # Verify the estimate belongs to this workspace and project before creating a point
+ estimate = Estimate.objects.filter(
+ pk=estimate_id,
+ workspace__slug=slug,
+ project_id=project_id,
+ ).first()
+ if not estimate:
+ return Response(
+ {"error": "Estimate not found"},
+ status=status.HTTP_404_NOT_FOUND,
+ )
key = request.data.get("key", 0)
value = request.data.get("value", "")
estimate_point = EstimatePoint.objects.create(
Source: GitHub Commit 971c2aa. The patch adds an explicit Estimate.objects.filter() with workspace__slug and project_id constraints before the create operation, returning HTTP 404 when the estimate does not belong to the specified scope.
Detection Methods for CVE-2026-104966
Indicators of Compromise
- PATCH requests to /api/workspaces/{slug}/projects/{project_id}/estimates/{estimate_id}/ where the responding record's workspace does not match the URL slug.
- POST requests to /api/workspaces/{slug}/projects/{project_id}/issues/{issue_id}/comments/ that create comments on issues belonging to a different workspace.
- Audit log entries showing comment or estimate changes attributed to a user who is not a member of the owning workspace.
Detection Strategies
- Correlate API access logs against workspace membership tables to find requests where the acting user has no role in the target workspace.
- Alert on sequential enumeration of estimate_id or issue_id values across different workspace slugs from a single user session.
- Review database triggers or audit tables for EstimatePoint or IssueComment writes attributed to users without matching workspace membership.
Monitoring Recommendations
- Enable verbose request logging on the Plane API gateway and capture authenticated user identifiers alongside URL path parameters.
- Monitor for anomalous HTTP 200/201 responses on estimate and comment endpoints following patch deployment, which should return HTTP 404 for out-of-scope identifiers.
- Track volume of PATCH and POST requests per user against estimate and comment endpoints to baseline normal activity.
How to Mitigate CVE-2026-104966
Immediate Actions Required
- Upgrade all Plane deployments to version 1.4.0 or later, as documented in the GitHub Release v1.4.0.
- Review audit logs for suspicious cross-workspace writes to estimates and issue comments since the vulnerable code was deployed.
- Rotate any workspace invitations or revoke sessions for users suspected of abusing the flaw.
Patch Information
The fix is included in Plane 1.4.0, delivered through commit 971c2aa and merged via Pull Request #9286. The patch enforces that nested resources are filtered by both workspace__slug and project_id before any mutation. Additional context is available in the GitHub Security Advisory GHSA-933r-rxg8-f3h2.
Workarounds
- If immediate upgrade is not possible, restrict access to the Plane API behind a reverse proxy that validates workspace slugs against the authenticated user's permitted workspaces.
- Limit workspace membership to trusted users until the patch is applied, since exploitation requires valid authentication.
- Disable or firewall off the affected estimates and comments endpoints at the ingress layer when they are not operationally required.
# Verify installed Plane version
docker exec -it plane-api cat /app/package.json | grep version
# Pull and deploy the patched release
docker compose pull
docker compose up -d
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.