Project Management Tool Plane Exposes Member Information to Unauthorized Users
CVE-2026-104962

6.5MEDIUM

Key Information:

Vendor

Makeplane

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-104962?

The Plane project management tool prior to version 1.4.0 has a significant security flaw that allows authenticated users to access sensitive information about project members across different projects within the same workspace. Specifically, the API endpoint responsible for listing project members inadvertently exposes comprehensive member details, including names and email addresses, to any user who is part of at least one project in the workspace. This lack of adequate permission checks presents potential privacy risks for users involved in projects, particularly in cases where sensitive data is handled.

Affected Version(s)

plane < 1.4.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.