CVE-2026-39374 | makeplane up to 1.2.x IssueBulkUpdateDateEndpoint start_date/target_date authorization (GHSA-4q54-h4x9-m329)
A vulnerability, which was classified as problematic, was found in makeplane plane up to 1.2.x. Affected by this vulnerability is an unknown functionality of the component IssueBulkUpdateDateEndpoint. The manipulation of the argument start_date/target_date results in authorization bypass.
This vulnerability was named CVE-2026-39374. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.