OVERVIEW CVE-2026-39374 is an authorization bypass vulnerability affecting Plane, an open-source project management tool, in versions prior to 1.3.0. The IssueBulkUpdateDateEndpoint fails to properly validate workspace and project membership, allowing authenticated project members with ADMIN or MEMBER roles to modify issue start and target dates across the entire Plane instance without proper access controls. SEVERITY The vulnerability carries a CVSS score of 7.7 (HIGH) with a network-based attack vector requiring low complexity and low privilege credentials. The primary impact is integrity compromise, as attackers can modify issue dates across unauthorized projects and workspaces. The CVSS vector indicates this is a low-effort attack requiring only network access and valid user credentials, with potential scope changes affecting multiple projects or workspaces. EXPLOITATION STATUS There is no evidence of active exploitation. The vulnerability does not appear on the Known Exploited Vulnerabilities catalog, and the EPSS score of 0.00031 indicates minimal probability of exploitation in the wild. No public exploit code is currently available, and the vulnerability remains inactive on threat intelligence hot lists. However, the moderate FAUCET Risk Score of 49.0/100 suggests organizations should prioritize patching to version 1.3.0.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.3.0CPE matchmatch criteria | cpe:2.3:a:plane:plane:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.