OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-105633

HIGH · CVSS 7.1 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-05 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The vulnerability affects the Plane project management tool prior to version 1.4.0, where the PATCH endpoint for issue attachments improperly validates the issue_id in the URL, allowing unauthorized users to modify attachments belonging to other users. This flaw can lead to unauthorized ownership transfer of attachments, posing a significant risk to data integrity and user privacy. Organizations using versions prior to 1.4.0 should prioritize updating to the latest version to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-105633
Severity
HIGH
CVSS
7.1
EPSS
0.30%

Original NVD Description

Plane is an open-source project management tool. Prior to 1.4.0, the V2 issue-attachment PATCH endpoint accepts issue_id in the URL but omits it from the database query. A project member can use an issue_id they control in the URL while targeting another user's attachment by its pk UUID. Because the server matches only pk, workspace, and project_id, it modifies the attachment regardless of the issue_id in the URL. When the attachment is pending and has not been confirmed as uploaded, the PATCH handler sets created_by = request.user and transfers attachment ownership to the attacker. This issue is fixed in 1.4.0.