---
id: CVE-2026-104966
title: Plane is an open-source project management tool
summary: >-
  Plane is an open-source project management tool. Prior to 1.4.0, two endpoint
  families fail to verify that nested resource identifiers belong to the
  workspace and project named in the URL. An authenticated user can read or
  modify estimat…
severity: high
cvss: 8.7
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'
cwe:
  - CWE-639
vendor: makeplane
product: plane
affected:
  - plane < 1.4.0
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T17:17:12.410'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104966'
references:
  - url: >-
      https://github.com/makeplane/plane/commit/971c2aadb4e848d70676b4f58b94bc7992dfe5fc
    label: security-advisories@github.com
  - url: 'https://github.com/makeplane/plane/pull/9286'
    label: security-advisories@github.com
  - url: 'https://github.com/makeplane/plane/releases/tag/v1.4.0'
    label: security-advisories@github.com
  - url: 'https://github.com/makeplane/plane/security/advisories/GHSA-933r-rxg8-f3h2'
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-05T17:27:45.052Z'
---

## Overview

Plane is an open-source project management tool. Prior to 1.4.0, two endpoint families fail to verify that nested resource identifiers belong to the workspace and project named in the URL. An authenticated user can read or modify estimates from another workspace through PATCH /api/workspaces/{slug}/projects/{project_id}/estimates/{estimate_id}/, and can inject comments into an issue from another workspace through POST /api/workspaces/{slug}/projects/{project_id}/issues/{issue_id}/comments/. ProjectEntityPermission verifies membership in the workspace and project from the URL, but estimate_id and issue_id are fetched by primary key without confirming the same scope. The list, retrieve, and destroy handlers correctly scope their queries, demonstrating the inconsistency. This issue is fixed in 1.4.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
