PT-2026-31005 · Plane · Plane
Tristaninsec
·
Published
2026-04-07
·
Updated
2026-04-08
·
CVE-2026-39374
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Plane versions prior to 1.3.0
Description
Plane, an open-source project management tool, has an issue where the
IssueBulkUpdateDateEndpoint allows a project member with ADMIN or MEMBER privileges to modify the start date and target date of any issue across the entire Plane instance, irrespective of workspace or project membership. The endpoint retrieves issues by ID without proper filtering, leading to cross-boundary data modification.Recommendations
Update to version 1.3.0 or later.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Plane