PT-2026-31005 · Makeplane · Plane

Published

2026-04-07

·

Updated

2026-04-07

·

CVE-2026-39374

CVSS v3.1

6.5

Medium

AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Plane is an an open-source project management tool. Prior to 1.3.0, the IssueBulkUpdateDateEndpoint allows a project member (ADMIN or MEMBER) to modify the start date and target date of ANY issue across the entire Plane instance, regardless of workspace or project membership. The endpoint fetches issues by ID without filtering by workspace or project, enabling cross-boundary data modification. This vulnerability is fixed in 1.3.0.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-39374

Affected Products

Plane