PT-2026-31005 · Plane · Plane

Tristaninsec

·

Published

2026-04-07

·

Updated

2026-04-08

·

CVE-2026-39374

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Plane versions prior to 1.3.0
Description Plane, an open-source project management tool, has an issue where the IssueBulkUpdateDateEndpoint allows a project member with ADMIN or MEMBER privileges to modify the start date and target date of any issue across the entire Plane instance, irrespective of workspace or project membership. The endpoint retrieves issues by ID without proper filtering, leading to cross-boundary data modification.
Recommendations Update to version 1.3.0 or later.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-39374

Affected Products

Plane