Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Syzygy-K

#50881of 57,613
5.4Total CVSS
Vulnerabilities · 1
PT-2026-106021
5.4
2026-10-05
Plane · Plane · CVE-2026-104955
**Name of the Vulnerable Software and Affected Versions** Plane versions prior to 1.4.0 **Description** An insufficient validation in the role-update logic allows a Project Member with role 15 to change another user's project role. By sending a PATCH request to the endpoint '/api/workspaces/{workspace slug}/projects/{project id}/members/{member pk}/', a requester can promote a Project Guest with role 5 to a Member role. This occurs because the system only blocks roles higher than the requester's, allowing the assignment of an equal role to bypass Project Admin approval and grant unauthorized project capabilities. **Recommendations** Update to version 1.4.0.