CVE-2026-105634
Deferred Deferred - Pending Action

Privilege Escalation in Plane Project Management Tool

Vulnerability report for CVE-2026-105634, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Plane is an open-source project management tool. Prior to 1.3.0, the ProjectMemberViewSet.partial_update method allows any project member, including a user with the lowest GUEST role, to modify another project member's role. The authorization check prevents assigning a role higher than the requester's role but does not prevent assigning a lower or equal role, allowing a Guest to demote Administrators and Members and deny them project control. This vulnerability is fixed in 1.3.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
makeplane plane < 1.3.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105634 is a privilege escalation vulnerability in Plane, an open-source project management tool. It affects versions before 1.3.0. The issue is in the ProjectMemberViewSet.partial_update method, which allows any project member, including a user with the GUEST role, to modify another member's role. The authorization check only prevents assigning a role higher than the requester's role but fails to block demotions, enabling a Guest to demote Admins or Members to the GUEST role.

Detection Guidance

To detect this vulnerability, check Plane software versions. Run: curl -s https://your-plane-instance.com/api/version | grep version. If version is below 1.3.0, the system is vulnerable. Also inspect network logs for unusual PATCH requests to /api/project-members/ with role modification payloads.

Impact Analysis

This vulnerability allows a low-privilege user (GUEST) to demote higher-privileged users (Admins, Members) to the GUEST role. This can lead to complete project takeover, as no one retains Admin access to manage members, settings, or deletion. Attackers can exploit this by sending crafted PATCH requests to modify roles.

Mitigation Strategies

Upgrade Plane to version 1.3.0 or later immediately. If upgrading is not possible, restrict access to the ProjectMemberViewSet.partial_update endpoint via network controls or disable role modification features until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105634. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart