CVE-2026-105632: Plane: Broken Access Control - joinProject GraphQL mutation allows self-join into private (secret) projects
Plane is an open-source project management tool. Prior to 1.4.0, the GraphQL joinProject mutation lets any workspace member add themselves to any project in that workspace including network=0 (secret/private) projects they were never invited to and grants them a full Member role (read + write). The resolver checks only workspace-level membership/role and never checks the target project's visibility (network). This collapses project-level tenant isolation within a workspace: a low-privilege member can read and modify confidential data in every private project. This issue is fixed in 1.4.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Planeto a version that resolves this vulnerability.Fixed in 1.4.0
Event History
Frequently Asked Questions
Who can exploit this issue?
Any existing member of an affected workspace can exploit it, including a low-privilege member. The attacker does not need a prior invitation to the target private project.
What access does successful exploitation provide?
The attacker can add themselves to any secret/private project in their workspace and receives the full Member role. This permits both reading and modifying confidential project data.
Are private projects protected by their visibility setting on affected versions?
No. The vulnerable joinProject resolver checks workspace membership or role but does not check the target project's network visibility, so network=0 secret/private projects are affected.
Which versions are affected and what is the remediation?
Plane versions before 1.4.0 are affected. Upgrade to version 1.4.0, which fixes the issue.