CVE-2026-104955: Plane: Project Member can escalate Project Guest to Member via PATCH /project-members/{pk} (BAC / Privilege Escalation)
Plane is an open-source project management tool. Prior to 1.4.0, a Project Member with role 15 can send a PATCH request to the project-member update endpoint at /api/workspaces/{workspaceslug}/projects/{projectid}/members/{memberpk}/ to change another user's project role. The role-update logic blocks only a new role higher than the requester's role, so assigning the equal Member role bypasses the insufficient validation and promotes a Project Guest with role 5 to Member without Project Admin approval. This unauthorized promotion grants the guest the additional project capabilities associated with the Member role and allows a regular member to bypass project governance controls. This issue is fixed in 1.4.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Planeto a version that resolves this vulnerability.Fixed in 1.4.0
Event History
Frequently Asked Questions
Which deployments are affected?
Plane versions prior to 1.4.0 are affected. The issue applies to projects where a user holds the Project Member role (role 15) and another user is a Project Guest (role 5).
What access does an attacker need?
An attacker must already be authenticated as a Project Member with role 15 in the target project. They can then send a PATCH request to the project-member update endpoint to promote another project user from Guest to Member.
Does exploiting this require Project Admin approval or user interaction?
No. A Project Member can promote a Project Guest to the equal Member role without Project Admin approval, and no user interaction is required.
What should teams do if they cannot immediately upgrade?
Restrict or closely monitor access to the project-member update endpoint for users holding the Project Member role, and review project membership changes for unauthorized Guest-to-Member promotions. Upgrading to Plane 1.4.0 fixes the issue.
How can administrators identify possible exploitation?
Review project membership records and available API or audit logs for PATCH requests to /api/workspaces/{workspace_slug}/projects/{project_id}/members/{member_pk}/ that changed a user's role from Project Guest (role 5) to Project Member (role 15).