Authorization Bypass in Project Management Tool by MakePlane
CVE-2026-104955

5.4MEDIUM

Key Information:

Vendor

Makeplane

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-104955?

The Plane project management tool exposed a vulnerability allowing a Project Member to send unauthorized PATCH requests, enabling them to change another user's project role without proper validation. Specifically, a Project Guest could be elevated to a Member role simply by matching the requester's role, circumventing the necessary approval from a Project Admin. This unauthorized access provides the guest with additional capabilities, compromising project governance controls. The issue has been fixed in version 1.4.0.

Affected Version(s)

plane < 1.4.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.