PT-2026-106021 · Plane · Plane

·

CVE-2026-104955

·

Published

2026-10-05

·

Updated

2026-10-05

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Plane versions prior to 1.4.0
Description An insufficient validation in the role-update logic allows a Project Member with role 15 to change another user's project role. By sending a PATCH request to the endpoint '/api/workspaces/{workspace slug}/projects/{project id}/members/{member pk}/', a requester can promote a Project Guest with role 5 to a Member role. This occurs because the system only blocks roles higher than the requester's, allowing the assignment of an equal role to bypass Project Admin approval and grant unauthorized project capabilities.
Recommendations Update to version 1.4.0.

Exploit

Fix

Improper Authorization

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-104955
GHSA-X63V-P7WC-47X4

Affected Products

Plane