PT-2026-106081 · Makeplane · Plane

·

CVE-2026-105634

·

Published

2026-10-05

·

Updated

2026-10-05

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Plane is an open-source project management tool. Prior to 1.3.0, the ProjectMemberViewSet.partial update method allows any project member, including a user with the lowest GUEST role, to modify another project member's role. The authorization check prevents assigning a role higher than the requester's role but does not prevent assigning a lower or equal role, allowing a Guest to demote Administrators and Members and deny them project control. This vulnerability is fixed in 1.3.0.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105634

Affected Products

Plane