CVE-2026-104893: Plane: Improper validation allows arbitrary modification of API token rate limits
Plane is an open-source project management tool. Prior to 1.4.0, GET /api/users/api-tokens/ allows an authenticated user to retrieve API-token records, while PATCH /api/users/api-tokens/{tokenid}/ allows the user to modify the token's allowedratelimit field without server-side validation or a maximum value. A user can raise the limit arbitrarily and bypass intended API rate-limiting controls, enabling high-volume automated requests, backend resource abuse, and possible resource exhaustion. This issue is fixed in 1.4.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
planeto a version that resolves this vulnerability.Fixed in 1.4.0
Event History
Frequently Asked Questions
Which deployments are affected?
Plane versions prior to 1.4.0 are affected. The exposed functionality is the authenticated API-token endpoints at GET /api/users/api-tokens/ and PATCH /api/users/api-tokens/{token_id}.
What access does an attacker need to exploit this issue?
An attacker needs an authenticated user account. No user interaction is required, and the attacker can use the API-token PATCH endpoint to set a token's allowed_rate_limit to an arbitrarily high value.
What is the practical impact of successful exploitation?
An authenticated user can bypass intended API rate-limiting controls for a token and make high-volume automated requests. This can enable backend resource abuse and possible resource exhaustion.
How can I determine whether a deployment is vulnerable?
A deployment is vulnerable if it runs a Plane version earlier than 1.4.0 and permits authenticated users to modify the allowed_rate_limit field through PATCH /api/users/api-tokens/{token_id}. Review API-token rate-limit values for unexpectedly high settings.
What should be done if upgrading is not immediately possible?
Restrict or disable authenticated access to the API-token modification endpoint where feasible, and monitor for tokens with unusually high allowed_rate_limit values or high-volume API activity. Upgrade to Plane 1.4.0 to obtain the fix.