Plane through 1.4.2 fails to validate that issues belong to the deploy board's project in the public comment endpoint. Authenticated attackers can post comments to arbitrary issues across workspaces by supplying an issue_id parameter to the public deploy-board comment endpoint.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 05 Sep 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Plane through 1.4.2 fails to validate that issues belong to the deploy board's project in the public comment endpoint. Authenticated attackers can post comments to arbitrary issues across workspaces by supplying an issue_id parameter to the public deploy-board comment endpoint. | |
| Title | Plane through 1.4.2 Arbitrary Comment Write via Public Deploy Board | |
| First Time appeared |
Plane
Plane plane |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:plane:plane:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Plane
Plane plane |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-05T11:01:26.069Z
Reserved: 2026-09-05T10:40:35.960Z
Link: CVE-2026-86174
No data.
Status : Received
Published: 2026-09-05T11:16:45.990
Modified: 2026-09-05T11:16:45.990
Link: CVE-2026-86174
No data.
OpenCVE Enrichment
Updated: 2026-09-05T14:00:04Z
Weaknesses