PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-104963 makeplane CVE debrief

CVE-2026-104963 debrief: Plane 1.4.0 fixes workspace cycle and module metadata exposure to any workspace member, addressing a vulnerability that allowed enumeration of private project metadata. Defenders managing Plane instances should assess exposure and upgrade to 1.4.0 to prevent metadata exposure. The vulnerability was caused by missing project-membership filters in workspace cycle and module endpoints, allowing authenticated workspace members to access private project information.

Vendor
makeplane
Product
plane
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-05
Original CVE updated
2026-10-07
Advisory published
2026-10-05
Advisory updated
2026-10-07

Who should care

Defenders managing Plane instances should assess exposure and upgrade to 1.4.0 to prevent metadata exposure. Affected operators, platform administrators, vulnerability management teams, and security teams should review the vulnerability's impact on their systems and take necessary actions to prevent exposure. This includes verifying exposure, upgrading to Plane 1.4.0, and reviewing workspace member access and project membership.

Why it matters

CVE-2026-104963: Plane workspace cycle and module endpoints missing project-membership filter exposes private project metadata to any workspace member. Defenders managing Plane instances should assess exposure and upgrade to 1.4.0.

  • Defenders must verify exposure and upgrade to Plane 1.4.0 to prevent metadata exposure
  • Authenticated workspace members can enumerate private project metadata
  • Project membership checks are required to prevent exposure

Technical summary

Plane 1.4.0 fixes workspace cycle and module metadata exposure to any workspace member. The vulnerability was caused by missing project-membership filters in workspace cycle and module endpoints, allowing authenticated workspace members to access private project information. Defenders should prioritize verifying exposure and upgrading to Plane 1.4.0 to prevent metadata exposure. The fix ensures that only authorized users can access project metadata, preventing unauthorized enumeration of private project information.

Defensive priority

Defenders should prioritize verifying exposure and upgrading to Plane 1.4.0

Recommended defensive actions

  • Verify exposure by checking if using Plane < 1.4.0
  • Upgrade to Plane 1.4.0 or later
  • Review workspace member access and project membership
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified

Evidence notes

The CVE record and Plane source references provide details on the vulnerability and fix. The vulnerability was reported and fixed in Plane version 1.4.0. Defenders should verify exposure by checking if using Plane < 1.4.0 and review workspace member access and project membership. Evidence is limited to public CVE and source information, and defenders should verify the vulnerability's impact on their systems.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-104963 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-104963

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-104963 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104963

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Plane: Workspace cycle and module endpoints missing project-membership filter expose private pro

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/104xxx/CVE-2026-104963.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/makeplane/plane/security/advisories/GHSA-wcc5-qgfr-8g9c

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/makeplane/plane/pull/9373

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/makeplane/plane/commit/b3591b9e6354f39715203787cc21f0cccd2cb3a9

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/makeplane/plane/releases/tag/v1.4.0

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.