Plane · Plane · CVE-2026-104893
**Name of the Vulnerable Software and Affected Versions**
Plane versions prior to 1.4.0
**Description**
An authenticated user can retrieve API-token records via the 'GET /api/users/api-tokens/' endpoint. Additionally, the 'PATCH /api/users/api-tokens/{token id}/' endpoint allows a user to modify the `allowed rate limit` field without server-side validation or a maximum value. This allows a user to arbitrarily increase the limit and bypass API rate-limiting controls, which can lead to high-volume automated requests, backend resource abuse, and potential resource exhaustion.
**Recommendations**
Update to version 1.4.0.