← Vulnerability feed

Vulnerability record · CVE-2026-40102 · published 20 May 2026

CVE-2026-40102: Plane vulnerability

Plane · Plane

Plane is an open-source project management tool. In versions 1.3.0 and below, SavedAnalyticEndpoint passes the user-controlled segment query parameter directly to a Django F() expression without validation (unlike the regular AnalyticsEndpoint, which checks against an allowlist), causing ORM Field Reference Injection. An authenticated workspace MEMBER can send GET /api/workspaces/<slug>/saved-analytic-view/<analytic_id>/ with a crafted segment value that is forwarded into build_graph_plot() and traverses foreign-key relationships (e.g. workspace__owner__password) before being projected via .values("dimension", "segment"), returning the referenced field values directly in the JSON response. This exposes sensitive data such as bcrypt password hashes, API tokens, and related users' email addresses, making it a stronger primitive than the related order_by injection where values are only leaked through ordering. This issue has been fixed in version 1.3.1.

6.5 CVSS 3.1 Medium EPSS 0.41% · top 67.6% CWE-943 · CWE-943
6.5CVSS 3.1 base score
0.41%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 2 tagged exploit
23 Jul 2026Last modified by NVD

Description

Plane is an open-source project management tool. In versions 1.3.0 and below, SavedAnalyticEndpoint passes the user-controlled segment query parameter directly to a Django F() expression without validation (unlike the regular AnalyticsEndpoint, which checks against an allowlist), causing ORM Field Reference Injection. An authenticated workspace MEMBER can send GET /api/workspaces/<slug>/saved-analytic-view/<analytic_id>/ with a crafted segment value that is forwarded into build_graph_plot() and traverses foreign-key relationships (e.g. workspace__owner__password) before being projected via .values("dimension", "segment"), returning the referenced field values directly in the JSON response. This exposes sensitive data such as bcrypt password hashes, API tokens, and related users' email addresses, making it a stronger primitive than the related order_by injection where values are only leaked through ordering. This issue has been fixed in version 1.3.1.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-40102 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.5CVE-2026-30242Plane server-side request forgery (ssrf) vulnerabilityPlane is an an open-source project management tool. Prior to version 1.2.3, the webhook URL validation in plane/app/serializers/webhook.py only check…EPSS 0.33%8.3CVE-2026-46558Plane insecure direct object reference vulnerabilityPlane is an open-source project management tool. Prior to version 1.3.1, there is a cross-workspace asset authorization bypass lets any authenticated…EPSS 0.40%7.7CVE-2026-39843Plane server-side request forgery (ssrf) vulnerabilityPlane is an an open-source project management tool. From 0.28.0 to before 1.3.0, the remediation of GHSA-jcc6-f9v6-f7jw is incomplete which could lea…EPSS 0.35%7.7CVE-2026-39374Plane insecure direct object reference vulnerabilityPlane is an an open-source project management tool. Prior to 1.3.0, the IssueBulkUpdateDateEndpoint allows a project member (ADMIN or MEMBER) to modi…EPSS 0.31%7.7CVE-2026-27706Plane server-side request forgery (ssrf) vulnerabilityPlane is an an open-source project management tool. Prior to version 1.2.2, a Full Read Server-Side Request Forgery (SSRF) vulnerability has been ide…EPSS 0.37%7.5CVE-2026-30244Plane information exposure vulnerabilityPlane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate workspace members and extract sen…EPSS 0.42%7.5CVE-2023-2268Plane missing authorization vulnerabilityPlane version 0.7.1 allows an unauthenticated attacker to view all stored server files of all users.EPSS 0.66%6.9CVE-2026-10850Plane cross-site scripting vulnerabilityPlane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when creating an intake work item thr…EPSS 0.17%

Source: NIST National Vulnerability Database (record CVE-2026-40102), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.