PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-39374 makeplane CVE debrief

CVE-2026-39374 is a vulnerability in the Plane open-source project management tool. Prior to version 1.3.0, a project member with ADMIN or MEMBER role could modify issue start_date and target_date across the entire Plane instance, regardless of workspace or project membership. The IssueBulkUpdateDateEndpoint did not filter issues by workspace or project, enabling cross-boundary data modification. This issue is fixed in version 1.3.0. Users of Plane project management tool versions prior to 1.3.0 should be aware of this vulnerability and take steps to upgrade to the latest version.

Vendor
makeplane
Product
plane
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-07
Original CVE updated
2026-07-24
Advisory published
2026-04-07
Advisory updated
2026-07-24

Who should care

Users of Plane project management tool versions prior to 1.3.0 should be aware of this vulnerability and take steps to upgrade to the latest version. Project administrators and members with ADMIN or MEMBER roles are particularly affected. They should review and restrict project member roles and permissions, and monitor issue date modifications for suspicious activity.

Technical summary

The IssueBulkUpdateDateEndpoint in Plane allowed unauthorized modification of issue dates across projects and workspaces. A project member (ADMIN or MEMBER) could change start_date and target_date of any issue. This was due to the endpoint not filtering issues by workspace or project. The vulnerability has a CVSS score of 6.5 and is classified as MEDIUM severity. It is fixed in version 1.3.0. Users should verify their deployments and plan for upgrades or mitigations. Project administrators and members with ADMIN or MEMBER roles are particularly affected. They should review and restrict project member roles and permissions, and monitor issue date modifications for suspicious activity. The CVE record was published on 2026-04-07T20:16:32.293Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. This vulnerability affects Plane project management tool versions prior to 1.3.0.

Defensive priority

Medium priority for Plane users and administrators to upgrade to version 1.3.0 or later and review configurations.

Recommended defensive actions

  • Upgrade to Plane version 1.3.0 or later
  • Review and restrict project member roles and permissions
  • Monitor issue date modifications for suspicious activity
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE record was published on 2026-04-07T20:16:32.293Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. This vulnerability affects Plane project management tool versions prior to 1.3.0. Users should verify their deployments and plan for upgrades or mitigations. The issue allows project members with ADMIN or MEMBER roles to modify issue dates across the entire Plane instance, regardless of workspace or project membership.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-07T20:16:32.293Z and has not been modified since then. The NVD entry is currently Analyzed.