CVE-2026-104969Medium· 6.5▾ SunlitPlane is an open-source project management tool. Prior to 1.4.0, the cycle-issues endpoint accepts issue UUIDs in the request body without validating that they belong to the caller's workspace. An authenticated user can add issues from a…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Plane is an open-source project management tool. Prior to 1.4.0, the cycle-issues endpoint accepts issue UUIDs in the request body without validating that they belong to the caller's workspace. An authenticated user can add issues from any workspace to a cycle they control. If a victim issue is already assigned to a cycle, the operation removes it from the victim's cycle, causing a destructive cross-tenant write. This issue is fixed in 1.4.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-104965Medium· 5.4Plane is an open-source project management tool
CVE-2026-104894Medium· 4.3Plane is an open-source project management tool
CVE-2026-104971High· 8.5Plane: Cross-Workspace Asset Duplication IDOR + WorkspaceFileAssetEndpoint and FileAssetEndpoint Missing Authorization
CVE-2026-104966High· 8.7Plane is an open-source project management tool
CVE-2026-104967Medium· 5.4Plane is an open-source project management tool
CVE-2026-104964Medium· 6.8Plane is an open-source project management tool