Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-39374

32
FAUCET Score

OVERVIEW CVE-2026-39374 is an authorization bypass vulnerability affecting Plane, an open-source project management tool, in versions prior to 1.3.0. The IssueBulkUpdateDateEndpoint fails to properly validate workspace and project membership, allowing authenticated project members with ADMIN or MEMBER roles to modify issue start and target dates across the entire Plane instance without proper access controls. SEVERITY The vulnerability carries a CVSS score of 7.7 (HIGH) with a network-based attack vector requiring low complexity and low privilege credentials. The primary impact is integrity compromise, as attackers can modify issue dates across unauthorized projects and workspaces. The CVSS vector indicates this is a low-effort attack requiring only network access and valid user credentials, with potential scope changes affecting multiple projects or workspaces. EXPLOITATION STATUS There is no evidence of active exploitation. The vulnerability does not appear on the Known Exploited Vulnerabilities catalog, and the EPSS score of 0.00031 indicates minimal probability of exploitation in the wild. No public exploit code is currently available, and the vulnerability remains inactive on threat intelligence hot lists. However, the moderate FAUCET Risk Score of 49.0/100 suggests organizations should prioritize patching to version 1.3.0.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.3.0CPE matchmatch criteria
cpe:2.3:a:plane:plane:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.21%
Probability of exploitation in next 30 days
EPSS Percentile
11.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0021 is in the 1st percentile among its peer group of 17,823 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

github_advisoryvendor investigatingvia nvd_reference
View patch

References

github.com / makeplane/plane/security/advisories/GHSA-4q54-h4x9-m329
ExploitVendor Advisory