OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-104966

HIGH · CVSS 8.7 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-05 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The vulnerability affects the Plane project management tool, allowing authenticated users to read or modify estimates and inject comments into issues across different workspaces due to insufficient verification of nested resource identifiers. This can lead to unauthorized access and manipulation of sensitive project data. Organizations using versions prior to 1.4.0 should prioritize upgrading to mitigate the risk of data breaches and maintain project integrity.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-104966
Severity
HIGH
CVSS
8.7
EPSS
0.25%

Original NVD Description

Plane is an open-source project management tool. Prior to 1.4.0, two endpoint families fail to verify that nested resource identifiers belong to the workspace and project named in the URL. An authenticated user can read or modify estimates from another workspace through PATCH /api/workspaces/{slug}/projects/{project_id}/estimates/{estimate_id}/, and can inject comments into an issue from another workspace through POST /api/workspaces/{slug}/projects/{project_id}/issues/{issue_id}/comments/. ProjectEntityPermission verifies membership in the workspace and project from the URL, but estimate_id and issue_id are fetched by primary key without confirming the same scope. The list, retrieve, and destroy handlers correctly scope their queries, demonstrating the inconsistency. This issue is fixed in 1.4.0.