CVE-2026-104893: Plane: Improper validation allows arbitrary modification of API token rate limits

Published Oct 5, 2026
·
Updated

Plane is an open-source project management tool. Prior to 1.4.0, GET /api/users/api-tokens/ allows an authenticated user to retrieve API-token records, while PATCH /api/users/api-tokens/{tokenid}/ allows the user to modify the token's allowedratelimit field without server-side validation or a maximum value. A user can raise the limit arbitrarily and bypass intended API rate-limiting controls, enabling high-volume automated requests, backend resource abuse, and possible resource exhaustion. This issue is fixed in 1.4.0.

Affected Software

1 affected component
Plane Plane<1.4.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade plane to a version that resolves this vulnerability.

    Fixed in 1.4.0

Event History

Oct 5, 2026
CVE Published
via MITRE·04:40 PM
Data Sourced
via MITRE·04:40 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are affected?

Plane versions prior to 1.4.0 are affected. The exposed functionality is the authenticated API-token endpoints at GET /api/users/api-tokens/ and PATCH /api/users/api-tokens/{token_id}.

2

What access does an attacker need to exploit this issue?

An attacker needs an authenticated user account. No user interaction is required, and the attacker can use the API-token PATCH endpoint to set a token's allowed_rate_limit to an arbitrarily high value.

3

What is the practical impact of successful exploitation?

An authenticated user can bypass intended API rate-limiting controls for a token and make high-volume automated requests. This can enable backend resource abuse and possible resource exhaustion.

4

How can I determine whether a deployment is vulnerable?

A deployment is vulnerable if it runs a Plane version earlier than 1.4.0 and permits authenticated users to modify the allowed_rate_limit field through PATCH /api/users/api-tokens/{token_id}. Review API-token rate-limit values for unexpectedly high settings.

5

What should be done if upgrading is not immediately possible?

Restrict or disable authenticated access to the API-token modification endpoint where feasible, and monitor for tokens with unusually high allowed_rate_limit values or high-volume API activity. Upgrade to Plane 1.4.0 to obtain the fix.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203