PT-2026-106021 · Plane · Plane
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Plane versions prior to 1.4.0
Description
An insufficient validation in the role-update logic allows a Project Member with role 15 to change another user's project role. By sending a PATCH request to the endpoint '/api/workspaces/{workspace slug}/projects/{project id}/members/{member pk}/', a requester can promote a Project Guest with role 5 to a Member role. This occurs because the system only blocks roles higher than the requester's, allowing the assignment of an equal role to bypass Project Admin approval and grant unauthorized project capabilities.
Recommendations
Update to version 1.4.0.
Exploit
Fix
Improper Authorization
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Plane