CVE-2026-86174

MEDIUMCVSS 4.3/10

Last modified

CVE-2026-86174 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Plane through 1.4.2 fails to validate that issues belong to the deploy board's project in the public comment endpoint. Authenticated attackers can post comments to arbitrary issues across workspaces by supplying an issue_id parameter to the public deploy-board comment endpoint..

Description

Plane through 1.4.2 fails to validate that issues belong to the deploy board's project in the public comment endpoint. Authenticated attackers can post comments to arbitrary issues across workspaces by supplying an issue_id parameter to the public deploy-board comment endpoint.

Metrics

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
makeplaneplane<= 1.4.2

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-86174?
Plane through 1.4.2 fails to validate that issues belong to the deploy board's project in the public comment endpoint. Authenticated attackers can post comments to arbitrary issues across workspaces by supplying an issue_id parameter to the public deploy-board comment endpoint.
How severe is CVE-2026-86174?
CVE-2026-86174 has a CVSS score of 4.3/10 (MEDIUM severity).
How do I fix CVE-2026-86174?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-86174?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST