CVE-2026-104955
Deferred Deferred - Pending Action

Unauthorized Role Promotion in Plane Project Management Tool

Vulnerability report for CVE-2026-104955, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Plane is an open-source project management tool. Prior to 1.4.0, a Project Member with role 15 can send a PATCH request to the project-member update endpoint at /api/workspaces/{workspace_slug}/projects/{project_id}/members/{member_pk}/ to change another user's project role. The role-update logic blocks only a new role higher than the requester's role, so assigning the equal Member role bypasses the insufficient validation and promotes a Project Guest with role 5 to Member without Project Admin approval. This unauthorized promotion grants the guest the additional project capabilities associated with the Member role and allows a regular member to bypass project governance controls. This issue is fixed in 1.4.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
makeplane plane < 1.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Plane allows a Project Member with role 15 to escalate a Project Guest (role 5) to a Project Member (role 15) without proper authorization. The issue occurs because the system incorrectly validates role changes by only blocking higher roles, allowing a Member to set another user's role to the same level. This bypasses governance controls and violates least privilege principles.

Detection Guidance

To detect this vulnerability, check Plane instances running versions prior to 1.4.0. Inspect API logs for PATCH requests to /api/workspaces/{workspace_slug}/projects/{project_id}/members/{member_pk}/ with role changes to 15 by non-admin users. Look for unauthorized role promotions from role 5 to 15 without Project Admin approval.

Impact Analysis

An attacker with Project Member access could escalate their privileges or those of another user to gain unauthorized project capabilities. This could lead to unauthorized access to sensitive project data, manipulation of project settings, or bypassing project governance controls. The attack requires low privileges and has low complexity.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements for data protection such as GDPR and HIPAA. It undermines access control and least privilege principles, which are critical for maintaining regulatory compliance.

Mitigation Strategies

Upgrade Plane to version 1.4.0 or later immediately. Review recent project member role changes for unauthorized promotions. Audit user roles and revoke any improperly assigned Member roles (role 15) that were granted without admin approval.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104955. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart