CVE-2026-104892
Deferred Deferred - Pending Action

Plane Project Management Tool API Key Exposure via Plaintext Logging

Vulnerability report for CVE-2026-104892, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Plane is an open-source project management tool. Prior to 1.4.0, aPITokenLogMiddleware logs API keys in plaintext. This allows someone with low privileges to steal user API keys and further escalate their privileges. This issue is fixed in 1.4.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
makeplane plane < 1.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-256 The product stores a password in plaintext within resources such as memory or files.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-104892 is a vulnerability in the Plane project management tool where the APITokenLogMiddleware logs API keys in plaintext. This affects versions up to 1.3.1. Low-privileged users can steal these API keys from logs and potentially escalate their privileges. The issue is fixed in version 1.4.0.

Detection Guidance

To detect this vulnerability, check Plane application logs for plaintext API keys in the file plane/apps/api/plane/middleware/logger.py. Search logs for X-Api-Key, Authorization headers, or Cookie values stored in plaintext. Use commands like grep -r 'X-Api-Key' /path/to/logs or grep -r 'Authorization:' /path/to/logs to identify exposed keys.

Impact Analysis

An attacker with low privileges could steal API keys from logs and use them to access sensitive data or perform unauthorized actions. This could lead to further privilege escalation within the Plane application or compromise of connected services using the stolen API keys.

Compliance Impact

Logging API keys in plaintext violates data protection principles by exposing sensitive credentials. This could lead to non-compliance with GDPR (data breaches) and HIPAA (unauthorized access to protected health information) due to inadequate protection of authentication tokens.

Mitigation Strategies

Upgrade Plane to version 1.4.0 or later to address the plaintext API key logging issue. Review and redact any logs containing API keys. Ensure API tokens are stored as SHA-256 hashes instead of plaintext. Remove MongoDB as a log sink and migrate logs to PostgreSQL.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104892. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart