CVE-2026-104955: Plane: Project Member can escalate Project Guest to Member via PATCH /project-members/{pk} (BAC / Privilege Escalation)

Published Oct 5, 2026
·
Updated

Plane is an open-source project management tool. Prior to 1.4.0, a Project Member with role 15 can send a PATCH request to the project-member update endpoint at /api/workspaces/{workspaceslug}/projects/{projectid}/members/{memberpk}/ to change another user's project role. The role-update logic blocks only a new role higher than the requester's role, so assigning the equal Member role bypasses the insufficient validation and promotes a Project Guest with role 5 to Member without Project Admin approval. This unauthorized promotion grants the guest the additional project capabilities associated with the Member role and allows a regular member to bypass project governance controls. This issue is fixed in 1.4.0.

Affected Software

1 affected component
Plane Plane<1.4.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Plane to a version that resolves this vulnerability.

    Fixed in 1.4.0

Event History

Oct 5, 2026
CVE Published
via MITRE·04:42 PM
Data Sourced
via MITRE·04:42 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are affected?

Plane versions prior to 1.4.0 are affected. The issue applies to projects where a user holds the Project Member role (role 15) and another user is a Project Guest (role 5).

2

What access does an attacker need?

An attacker must already be authenticated as a Project Member with role 15 in the target project. They can then send a PATCH request to the project-member update endpoint to promote another project user from Guest to Member.

3

Does exploiting this require Project Admin approval or user interaction?

No. A Project Member can promote a Project Guest to the equal Member role without Project Admin approval, and no user interaction is required.

4

What should teams do if they cannot immediately upgrade?

Restrict or closely monitor access to the project-member update endpoint for users holding the Project Member role, and review project membership changes for unauthorized Guest-to-Member promotions. Upgrading to Plane 1.4.0 fixes the issue.

5

How can administrators identify possible exploitation?

Review project membership records and available API or audit logs for PATCH requests to /api/workspaces/{workspace_slug}/projects/{project_id}/members/{member_pk}/ that changed a user's role from Project Guest (role 5) to Project Member (role 15).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203