Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-39843

26
FAUCET Score

Plane, an open-source project management tool, contains an incomplete remediation of a prior Server-Side Request Forgery vulnerability affecting versions 0.28.0 through 1.2.x. The flaw allows authenticated attackers with low privileges to bypass validation controls by exploiting the favicon fetch functionality, which does not properly validate redirects to private IP addresses when processing HTML link tags. The vulnerability was resolved in version 1.3.0. The vulnerability carries a CVSS score of 7.7 (High) with a network-based attack vector requiring low privileges and no user interaction. The attack has a low complexity rating and could result in high confidentiality impact with cross-site scope, allowing unauthorized access to sensitive information from internal systems. This represents a notable privilege escalation from typical unauthenticated SSRF vulnerabilities. There is currently no evidence of active exploitation in the wild, with an EPSS score of 0.00033 indicating minimal real-world exploitation activity to date. No public exploit code has been disclosed, and the vulnerability has not been added to CISA's Known Exploited Vulnerabilities catalog. Organizations using affected Plane versions should prioritize upgrading to version 1.3.0 to remediate this risk.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0.28.0, < 1.3.0CPE matchmatch criteria
cpe:2.3:a:plane:plane:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.7HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.1
Impact Score
4.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.25%
Probability of exploitation in next 30 days
EPSS Percentile
15.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0025 is in the 4th percentile among its peer group of 17,844 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / makeplane/plane/security/advisories/GHSA-9fr2-pprw-pp9j
ExploitVendor Advisory