CVE-2026-105629

Published: Ott 05, 2026 Last Modified: Ott 05, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,1
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: high
Availability: low

Description

AI Translation Available

Plane is an open-source project management tool. Prior to 1.4.0, BulkEstimatePointEndpoint.destroy resolves an estimate point through a bare primary-key lookup without workspace, project, or estimate scoping. An administrator or member of one workspace can permanently delete an estimate point belonging to another workspace by supplying the target UUID in a URL under the attacker's own workspace. This creates a destructive cross-tenant IDOR. This issue is fixed in 1.4.0.

639

Authorization Bypass Through User-Controlled Key

Incomplete
Common Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Bypass Protection Mechanism Gain Privileges Or Assume Identity
Applicable Platforms
All platforms may be affected
View CWE Details
https://github.com/makeplane/plane/commit/971c2aadb4e848d70676b4f58b94bc7992dfe…
https://github.com/makeplane/plane/pull/9286
https://github.com/makeplane/plane/releases/tag/v1.4.0
https://github.com/makeplane/plane/security/advisories/GHSA-7mr3-6cgx-3j95