Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Oct 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Plane is an open-source project management tool. Prior to 1.4.0, the issue-relation endpoint accepts issue UUIDs in the request body without validating that they belong to the caller's workspace. An authenticated user can create relations linking their own issues to issues in any other workspace on the instance, leaking issue metadata through activity events. This issue is fixed in 1.4.0. | |
| Title | Plane: Cross-Tenant Issue Relation Creation via IDOR | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-05T17:49:49.310Z
Reserved: 2026-10-02T18:16:13.629Z
Link: CVE-2026-104965
No data.
Status : Deferred
Published: 2026-10-05T17:17:12.103
Modified: 2026-10-05T17:17:12.243
Link: CVE-2026-104965
No data.
OpenCVE Enrichment
No data.
