Plane · Plane · CVE-2026-104955
**Name of the Vulnerable Software and Affected Versions**
Plane versions prior to 1.4.0
**Description**
An insufficient validation in the role-update logic allows a Project Member with role 15 to change another user's project role. By sending a PATCH request to the endpoint '/api/workspaces/{workspace slug}/projects/{project id}/members/{member pk}/', a requester can promote a Project Guest with role 5 to a Member role. This occurs because the system only blocks roles higher than the requester's, allowing the assignment of an equal role to bypass Project Admin approval and grant unauthorized project capabilities.
**Recommendations**
Update to version 1.4.0.