Project Management Tool Plane Exposes Member Information to Unauthorized Users
CVE-2026-104962
6.5MEDIUM
What is CVE-2026-104962?
The Plane project management tool prior to version 1.4.0 has a significant security flaw that allows authenticated users to access sensitive information about project members across different projects within the same workspace. Specifically, the API endpoint responsible for listing project members inadvertently exposes comprehensive member details, including names and email addresses, to any user who is part of at least one project in the workspace. This lack of adequate permission checks presents potential privacy risks for users involved in projects, particularly in cases where sensitive data is handled.
Affected Version(s)
plane < 1.4.0
