CVE-2026-86174
Plane through 1.4.2 fails to validate that issues belong to the deploy board's project in the public comment endpoint. Authenticated attacke
CVSS
4.3
Medium
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Sep 5, 2026 · Last modified: Sep 5, 2026 · CWE-639
Not enough EPSS history yet.
Plane through 1.4.2 fails to validate that issues belong to the deploy board's project in the public comment endpoint. Authenticated attackers can post comments to arbitrary issues across workspaces by supplying an issue_id parameter to the public deploy-board comment endpoint.
- github.comhttps://github.com/makeplane/plane
- github.comhttps://github.com/makeplane/plane/blob/v1.4.2/apps/api/plane/space/views/issue.py#L258-L275
- github.comhttps://github.com/makeplane/plane/issues/9441
- www.vulncheck.comhttps://www.vulncheck.com/advisories/plane-through-1.4.2-arbitrary-comment-write-via-public-deploy-board
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-861764.3 MED—
——0NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscriptions, and Bookmarks. Authenticated users with view permissions can access all users' private records through unscoped querysets, disclosing which users watch or bookmark which objects.4hCVE-2026-861136.5 MED—
——0BookWyrm through 0.9.1 contains an authorization bypass vulnerability in the edit_readthrough function that allows authenticated users to modify other users' reading records. Attackers can exploit sequential ReadThrough IDs to overwrite arbitrary users' start dates, finish dates, progress, and progress mode, affecting reading statistics and exported data.5hCVE-2026-861125.4 MED—
——0BookWyrm through 0.9.1 fails to validate user visibility permissions in the Favorite and Unfavorite views, allowing authenticated attackers to favorite or unfavorite followers-only and direct statuses they cannot access. Attackers can POST to the favorite endpoint with a status ID to create unauthorized interactions, trigger ActivityPub broadcasts, and enumerate private status IDs through response differentiation.5hCVE-2026-861116.5 MED—
——0BookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint, allowing authenticated attackers to read followers-only and direct-message reviews by enumerating sequential status IDs. Attackers can access the raw content of restricted statuses through the edit view, bypassing the privacy protections documented for these message types.5hCVE-2026-856387.3 HIG—
——0A weakness has been identified in jofpin trape 2.0. This affects an unknown part of the file core/user.py. This manipulation of the argument vId/id causes authorization bypass. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.20hCVE-2026-616886.5 MED—
——0SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, an authenticated user can view the API request history of any other user's API tokens within the same company by manipulating two writable Symfony UX LiveComponent props on the `DataGrid` component. Version 3.0.1 fixes the issue.21h