CVE-2026-105629 Overview
Plane is an open-source project management tool used by teams to coordinate work across multiple workspaces and projects. CVE-2026-105629 is a cross-tenant Insecure Direct Object Reference (IDOR) vulnerability [CWE-639] in the BulkEstimatePointEndpoint.destroy handler. The endpoint resolves an estimate point through a bare primary-key lookup without validating workspace, project, or estimate scoping. An authenticated administrator or member of one workspace can permanently delete an estimate point belonging to a different workspace by supplying the target UUID in a URL under their own workspace. Plane versions prior to 1.4.0 are affected, and the issue is fixed in 1.4.0.
Critical Impact
Any authenticated workspace member can permanently delete estimate point records belonging to unrelated tenants, causing cross-tenant data loss and integrity damage.
Affected Products
- Plane (makeplane/plane) versions prior to 1.4.0
- Self-hosted Plane deployments running vulnerable apps/api/plane/app/views/estimate/base.py
- Multi-tenant Plane instances serving multiple workspaces
Discovery Timeline
- 2026-10-05 - CVE-2026-105629 published to NVD
- 2026-10-06 - Last updated in NVD database
- v1.4.0 - Plane releases patched version with workspace and project scoping
Technical Details for CVE-2026-105629
Vulnerability Analysis
The vulnerability resides in the BulkEstimatePointEndpoint.destroy method within Plane's estimate API. The handler accepts an estimate point identifier from the URL and performs a direct primary-key lookup against the EstimatePoint model. The query does not constrain results by the requesting user's workspace slug or project identifier. As a result, the server treats any valid UUID as a legitimate target regardless of ownership.
An attacker leverages this by issuing a destroy request under a workspace they legitimately control, substituting the UUID of an estimate point from an unrelated workspace. The ORM returns the foreign record, and the handler proceeds to delete it. The impact is loss of integrity and limited availability for the victim tenant, as estimate point data is permanently removed.
Root Cause
The root cause is missing authorization scoping on object retrieval, classified under [CWE-639] Authorization Bypass Through User-Controlled Key. The handler trusts the URL parameter without verifying that the referenced estimate belongs to the workspace and project in the request path.
Attack Vector
Exploitation requires network access to the Plane API and a valid account with workspace membership. No user interaction is required. The attacker only needs the target UUID, which may be obtained through social sources, prior access, or enumeration.
{"error": "Key and value are required"},
status=status.HTTP_400_BAD_REQUEST,
)
+ # Verify the estimate belongs to this workspace and project before creating a point
+ estimate = Estimate.objects.filter(
+ pk=estimate_id,
+ workspace__slug=slug,
+ project_id=project_id,
+ ).first()
+ if not estimate:
+ return Response(
+ {"error": "Estimate not found"},
+ status=status.HTTP_404_NOT_FOUND,
+ )
key = request.data.get("key", 0)
value = request.data.get("value", "")
estimate_point = EstimatePoint.objects.create(
Source: GitHub Commit 971c2aa. The patch adds an explicit filter on workspace__slug and project_id before any mutation, returning HTTP 404 when the estimate does not belong to the requesting scope.
Detection Methods for CVE-2026-105629
Indicators of Compromise
- DELETE requests to estimate point endpoints where the resolved workspace_id of the target record does not match the slug in the request URL.
- Unexpected deletions of EstimatePoint rows with no corresponding user activity in the owning workspace's audit history.
- API 2xx responses on estimate destroy routes originating from accounts with no membership in the target workspace.
Detection Strategies
- Correlate API access logs against workspace membership records to flag cross-workspace object references.
- Add server-side logging that records the resolved object's workspace alongside the URL workspace slug for every estimate mutation.
- Review database audit trails for EstimatePoint deletions and reconcile them against authenticated session workspace scope.
Monitoring Recommendations
- Monitor the Plane API gateway for anomalous DELETE volume against /api/v1/workspaces/{slug}/projects/{id}/estimates/ paths.
- Alert on repeated 404 responses from estimate endpoints, which may indicate UUID enumeration attempts.
- Track per-user deletion rates on multi-tenant Plane instances and investigate statistical outliers.
How to Mitigate CVE-2026-105629
Immediate Actions Required
- Upgrade all Plane instances to version 1.4.0 or later, which includes the authorization scoping fix.
- Audit EstimatePoint tables for recent unexplained deletions and restore from backups if cross-tenant deletion is confirmed.
- Rotate API tokens for any accounts suspected of abusing the endpoint during the vulnerable window.
Patch Information
The fix is published in Plane v1.4.0 and tracked in Pull Request #9286. Full technical details are available in the GitHub Security Advisory GHSA-7mr3-6cgx-3j95. The patch adds workspace and project scoping to estimate lookups in apps/api/plane/app/views/estimate/base.py.
Workarounds
- Restrict API access to the vulnerable estimate endpoints via reverse proxy rules until the upgrade is applied.
- Limit workspace membership to trusted users on multi-tenant instances to reduce the pool of potential attackers.
- Enforce database-level backups of estimate tables so that malicious deletions can be rapidly reverted.
# Upgrade Plane via Docker Compose
git fetch --tags
git checkout v1.4.0
docker compose pull
docker compose up -d
# Verify running version
docker compose exec api python -c "import plane; print(plane.__version__)"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.