PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-39374 makeplane CVE debrief

CVE-2026-39374 is a vulnerability in the Plane open-source project management tool. Prior to version 1.3.0, a project member with ADMIN or MEMBER role could modify issue start_date and target_date across the entire Plane instance, regardless of workspace or project membership. The IssueBulkUpdateDateEndpoint did not filter issues by workspace or project, enabling cross-boundary data modification. This issue is fixed in version 1.3.0. Users of Plane project management tool versions prior to 1.3.0 should be aware of this vulnerability and take steps to upgrade to the latest version.

Vendor
makeplane
Product
plane
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-07
Original CVE updated
2026-07-24
Advisory published
2026-04-07
Advisory updated
2026-07-24

Who should care

Users of Plane project management tool versions prior to 1.3.0 should be aware of this vulnerability and take steps to upgrade to the latest version. Project administrators and members with ADMIN or MEMBER roles are particularly affected. They should review and restrict project member roles and permissions, and monitor issue date modifications for suspicious activity.

Technical summary

The IssueBulkUpdateDateEndpoint in Plane allowed unauthorized modification of issue dates across projects and workspaces. A project member (ADMIN or MEMBER) could change start_date and target_date of any issue. This was due to the endpoint not filtering issues by workspace or project. The vulnerability has a CVSS score of 6.5 and is classified as MEDIUM severity. It is fixed in version 1.3.0. Users should verify their deployments and plan for upgrades or mitigations. Project administrators and members with ADMIN or MEMBER roles are particularly affected. They should review and restrict project member roles and permissions, and monitor issue date modifications for suspicious activity. The CVE record was published on 2026-04-07T20:16:32.293Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. This vulnerability affects Plane project management tool versions prior to 1.3.0.

Defensive priority

Medium priority for Plane users and administrators to upgrade to version 1.3.0 or later and review configurations.

Recommended defensive actions

  • Upgrade to Plane version 1.3.0 or later
  • Review and restrict project member roles and permissions
  • Monitor issue date modifications for suspicious activity
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE record was published on 2026-04-07T20:16:32.293Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. This vulnerability affects Plane project management tool versions prior to 1.3.0. Users should verify their deployments and plan for upgrades or mitigations. The issue allows project members with ADMIN or MEMBER roles to modify issue dates across the entire Plane instance, regardless of workspace or project membership.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-39374 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-39374

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-39374 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-39374

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.