← Vulnerability feed

Vulnerability record · CVE-2026-39374 · published 7 April 2026

CVE-2026-39374: Plane insecure direct object reference vulnerability

Plane · Plane

Plane is an an open-source project management tool. Prior to 1.3.0, the IssueBulkUpdateDateEndpoint allows a project member (ADMIN or MEMBER) to modify the start_date and target_date of ANY issue across the entire Plane instance, regardless of workspace or project membership. The endpoint fetches issues by ID without filtering by workspace or project, enabling cross-boundary data modification. This vulnerability is fixed in 1.3.0.

7.7 CVSS 3.1 High EPSS 0.31% · top 78.7% CWE-639 · Insecure direct object reference
7.7CVSS 3.1 base score
0.31%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References, 1 tagged exploit
24 Jul 2026Last modified by NVD

Description

Plane is an an open-source project management tool. Prior to 1.3.0, the IssueBulkUpdateDateEndpoint allows a project member (ADMIN or MEMBER) to modify the start_date and target_date of ANY issue across the entire Plane instance, regardless of workspace or project membership. The endpoint fetches issues by ID without filtering by workspace or project, enabling cross-boundary data modification. This vulnerability is fixed in 1.3.0.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-39374 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.5CVE-2026-30242Plane server-side request forgery (ssrf) vulnerabilityPlane is an an open-source project management tool. Prior to version 1.2.3, the webhook URL validation in plane/app/serializers/webhook.py only check…EPSS 0.33%8.3CVE-2026-46558Plane insecure direct object reference vulnerabilityPlane is an open-source project management tool. Prior to version 1.3.1, there is a cross-workspace asset authorization bypass lets any authenticated…EPSS 0.40%7.7CVE-2026-39843Plane server-side request forgery (ssrf) vulnerabilityPlane is an an open-source project management tool. From 0.28.0 to before 1.3.0, the remediation of GHSA-jcc6-f9v6-f7jw is incomplete which could lea…EPSS 0.35%7.7CVE-2026-27706Plane server-side request forgery (ssrf) vulnerabilityPlane is an an open-source project management tool. Prior to version 1.2.2, a Full Read Server-Side Request Forgery (SSRF) vulnerability has been ide…EPSS 0.37%7.5CVE-2026-30244Plane information exposure vulnerabilityPlane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate workspace members and extract sen…EPSS 0.42%7.5CVE-2023-2268Plane missing authorization vulnerabilityPlane version 0.7.1 allows an unauthenticated attacker to view all stored server files of all users.EPSS 0.66%6.9CVE-2026-10850Plane cross-site scripting vulnerabilityPlane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when creating an intake work item thr…EPSS 0.17%6.5CVE-2026-40102Plane vulnerabilityPlane is an open-source project management tool. In versions 1.3.0 and below, SavedAnalyticEndpoint passes the user-controlled segment query paramete…EPSS 0.41%

Source: NIST National Vulnerability Database (record CVE-2026-39374), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.