Plane through 1.4.2 fails to validate that issues belong to the deploy board's project in the public comment endpoint. Authenticated attackers can post comments to arbitrary issues across workspaces by supplying an issue_id parameter to the public deploy-board comment endpoint.
Metrics
Affected Vendors & Products
References
History
Thu, 10 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 05 Sep 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Plane through 1.4.2 fails to validate that issues belong to the deploy board's project in the public comment endpoint. Authenticated attackers can post comments to arbitrary issues across workspaces by supplying an issue_id parameter to the public deploy-board comment endpoint. | |
| Title | Plane through 1.4.2 Arbitrary Comment Write via Public Deploy Board | |
| First Time appeared |
Plane
Plane plane |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:plane:plane:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Plane
Plane plane |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-09-05T11:01:26.069Z
Updated: 2026-09-10T15:05:35.907Z
Reserved: 2026-09-05T10:40:35.960Z
Link: CVE-2026-86174
Updated: 2026-09-10T14:19:12.867Z
Status : Received
Published: 2026-09-05T11:16:45.990
Modified: 2026-09-10T16:18:01.810
Link: CVE-2026-86174
No data.