SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-86174

MEDIUM · CVSS 4.3 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-05 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability allows authenticated attackers to exploit the public comment endpoint in Plane through version 1.4.2, enabling them to post comments to arbitrary issues by manipulating the issue_id parameter. This could lead to unauthorized information disclosure or misinformation across workspaces. Organizations using this version of Plane should prioritize remediation to mitigate potential impacts on project integrity and security.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-86174
Severity
MEDIUM
CVSS
4.3
EPSS
0.20%

Original NVD Description

Plane through 1.4.2 fails to validate that issues belong to the deploy board's project in the public comment endpoint. Authenticated attackers can post comments to arbitrary issues across workspaces by supplying an issue_id parameter to the public deploy-board comment endpoint.