CVE-2026-105632
Deferred Deferred - Pending Action

Unauthorized Project Access in Plane Prior to 1.4.0

Vulnerability report for CVE-2026-105632, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Plane is an open-source project management tool. Prior to 1.4.0, the GraphQL joinProject mutation lets any workspace member add themselves to any project in that workspace including network=0 (secret/private) projects they were never invited to and grants them a full Member role (read + write). The resolver checks only workspace-level membership/role and never checks the target project's visibility (network). This collapses project-level tenant isolation within a workspace: a low-privilege member can read and modify confidential data in every private project. This issue is fixed in 1.4.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
makeplane plane < 1.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105632 is a broken access control flaw in Plane, an open-source project management tool. It affects versions 1.3.1 and earlier. The vulnerability exists in the GraphQL joinProject mutation, which allows any workspace member to add themselves to any project in the workspace, including private projects they were never invited to. This grants them full Member role access (read and write permissions). The issue occurs because the resolver only checks workspace-level membership and role but does not verify the target project's visibility setting.

Detection Guidance

Check Plane software version with: docker inspect plane-app | grep VERSION. If version is 1.3.1 or earlier, the system is vulnerable. Review GraphQL API logs for unauthorized joinProject mutations or unexpected project membership changes.

Impact Analysis

This vulnerability allows low-privilege workspace members to access and modify confidential data in private projects they were not invited to. It collapses project-level tenant isolation within a workspace, enabling unauthorized read and write access to sensitive information. Attackers can exploit this by using the GraphQL mutation to join private projects, bypassing intended access restrictions.

Compliance Impact

This vulnerability can lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR, HIPAA, and other regulations. It compromises data confidentiality and integrity by allowing unauthorized users to read and modify private project data, potentially resulting in data breaches and non-compliance with privacy and security standards.

Mitigation Strategies

Upgrade Plane to version 1.4.0 or later immediately. Review all workspace members and project access permissions. Audit GraphQL mutation logs for unauthorized project joins. Implement additional validation checks for project visibility in joinProject resolver.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105632. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart