PT-2026-106030 · Plane · Plane

·

CVE-2026-104962

·

Published

2026-10-05

·

Updated

2026-10-05

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Plane versions prior to 1.4.0
Description An issue exists where the endpoint "/api/v1/workspaces/{slug}/projects/{project id}/members/" returns the complete project-member roster, including email addresses, names, avatars, and roles. The ProjectMemberPermission check only verifies if the caller is an active member of any project within the workspace, failing to bind the check to the specific project id. As a result, any authenticated user, including those with Guest roles, can access the member list of other private projects within the same workspace by manipulating the project id variable in the URL.
Recommendations Update to version 1.4.0.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-104962
GHSA-W2VF-M9X9-MVMC

Affected Products

Plane