Authorization Bypass in Project Management Tool by MakePlane
CVE-2026-104955
5.4MEDIUM
What is CVE-2026-104955?
The Plane project management tool exposed a vulnerability allowing a Project Member to send unauthorized PATCH requests, enabling them to change another user's project role without proper validation. Specifically, a Project Guest could be elevated to a Member role simply by matching the requester's role, circumventing the necessary approval from a Project Admin. This unauthorized access provides the guest with additional capabilities, compromising project governance controls. The issue has been fixed in version 1.4.0.
Affected Version(s)
plane < 1.4.0
