Description
Plane is an open-source project management tool. Prior to 1.4.0, a Project Member with role 15 can send a PATCH request to the project-member update endpoint at /api/workspaces/{workspace_slug}/projects/{project_id}/members/{member_pk}/ to change another user's project role. The role-update logic blocks only a new role higher than the requester's role, so assigning the equal Member role bypasses the insufficient validation and promotes a Project Guest with role 5 to Member without Project Admin approval. This unauthorized promotion grants the guest the additional project capabilities associated with the Member role and allows a regular member to bypass project governance controls. This issue is fixed in 1.4.0.
Published: 2026-10-05
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

Plane is an open‑source project‑management platform. A Project Member with role ID 15 can send a PATCH request to /api/workspaces/{workspace_slug}/projects/{project_id}/members/{member_pk}/ to change another user's role. The existing logic only blocks assigning a role higher than the requester's role; assigning an equal role bypasses validation, allowing a Project Guest (role 5) to be promoted to Member without Project Admin approval. This unauthorized promotion grants the guest the expanded capabilities of a Member and lets a regular member bypass project governance.

Affected Systems

All deployments of makeplane:plane running any release older than v1.4.0 are affected. The vulnerability was introduced prior to version 1.4.0 and is fixed in that release. Users should verify their current version and upgrade accordingly.

Risk and Exploitability

CVSS score of 5.4 indicates a moderate‑severity flaw. The vulnerability is exploitable via an authenticated PATCH request to the project‑member update endpoint. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. An attacker who can act as a Project Member can promote another guest to a Member, thus gaining additional project privileges without administrative oversight.

Generated by OpenCVE AI on October 5, 2026 at 18:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Plane version 1.4.0 or later to apply the patch that enforces stricter role change logic.
  • If immediate upgrade is not possible, temporarily restrict access to the role‑update endpoint so that only Project Admins can modify user roles, or enforce a check that the new role is strictly higher than the requester's role.
  • Regularly audit role assignments for unexpected promotions and revoke any unauthorized changes to ensure project governance is maintained.

Generated by OpenCVE AI on October 5, 2026 at 18:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Makeplane
Makeplane plane
Vendors & Products Makeplane
Makeplane plane

Mon, 05 Oct 2026 17:00:00 +0000

Type Values Removed Values Added
Description Plane is an open-source project management tool. Prior to 1.4.0, a Project Member with role 15 can send a PATCH request to the project-member update endpoint at /api/workspaces/{workspace_slug}/projects/{project_id}/members/{member_pk}/ to change another user's project role. The role-update logic blocks only a new role higher than the requester's role, so assigning the equal Member role bypasses the insufficient validation and promotes a Project Guest with role 5 to Member without Project Admin approval. This unauthorized promotion grants the guest the additional project capabilities associated with the Member role and allows a regular member to bypass project governance controls. This issue is fixed in 1.4.0.
Title Plane: Project Member can escalate Project Guest to Member via PATCH /project-members/{pk} (BAC / Privilege Escalation)
Weaknesses CWE-269
CWE-285
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-05T16:42:25.771Z

Reserved: 2026-10-02T18:16:13.628Z

Link: CVE-2026-104955

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-05T17:17:10.970

Modified: 2026-10-05T17:17:11.110

Link: CVE-2026-104955

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T18:30:19Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-285

    Improper Authorization