PatchSiren cyber security CVE debrief
CVE-2026-104963 makeplane CVE debrief
CVE-2026-104963 debrief: Plane 1.4.0 fixes workspace cycle and module metadata exposure to any workspace member, addressing a vulnerability that allowed enumeration of private project metadata. Defenders managing Plane instances should assess exposure and upgrade to 1.4.0 to prevent metadata exposure. The vulnerability was caused by missing project-membership filters in workspace cycle and module endpoints, allowing authenticated workspace members to access private project information.
- Vendor
- makeplane
- Product
- plane
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-05
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-05
- Advisory updated
- 2026-10-07
Who should care
Defenders managing Plane instances should assess exposure and upgrade to 1.4.0 to prevent metadata exposure. Affected operators, platform administrators, vulnerability management teams, and security teams should review the vulnerability's impact on their systems and take necessary actions to prevent exposure. This includes verifying exposure, upgrading to Plane 1.4.0, and reviewing workspace member access and project membership.
Why it matters
CVE-2026-104963: Plane workspace cycle and module endpoints missing project-membership filter exposes private project metadata to any workspace member. Defenders managing Plane instances should assess exposure and upgrade to 1.4.0.
- Defenders must verify exposure and upgrade to Plane 1.4.0 to prevent metadata exposure
- Authenticated workspace members can enumerate private project metadata
- Project membership checks are required to prevent exposure
Technical summary
Plane 1.4.0 fixes workspace cycle and module metadata exposure to any workspace member. The vulnerability was caused by missing project-membership filters in workspace cycle and module endpoints, allowing authenticated workspace members to access private project information. Defenders should prioritize verifying exposure and upgrading to Plane 1.4.0 to prevent metadata exposure. The fix ensures that only authorized users can access project metadata, preventing unauthorized enumeration of private project information.
Defensive priority
Defenders should prioritize verifying exposure and upgrading to Plane 1.4.0
Recommended defensive actions
- Verify exposure by checking if using Plane < 1.4.0
- Upgrade to Plane 1.4.0 or later
- Review workspace member access and project membership
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
Evidence notes
The CVE record and Plane source references provide details on the vulnerability and fix. The vulnerability was reported and fixed in Plane version 1.4.0. Defenders should verify exposure by checking if using Plane < 1.4.0 and review workspace member access and project membership. Evidence is limited to public CVE and source information, and defenders should verify the vulnerability's impact on their systems.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-104963 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-104963
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-104963 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104963
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Plane: Workspace cycle and module endpoints missing project-membership filter expose private pro
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/104xxx/CVE-2026-104963.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/makeplane/plane/security/advisories/GHSA-wcc5-qgfr-8g9c
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/makeplane/plane/pull/9373
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/makeplane/plane/commit/b3591b9e6354f39715203787cc21f0cccd2cb3a9
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/makeplane/plane/releases/tag/v1.4.0
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.