CVE-2026-105634: Plane: Privilege Escalation: Project Guest Can Demote Admin/Member Roles

Published Oct 5, 2026
·
Updated

Plane is an open-source project management tool. Prior to 1.3.0, the ProjectMemberViewSet.partialupdate method allows any project member, including a user with the lowest GUEST role, to modify another project member's role. The authorization check prevents assigning a role higher than the requester's role but does not prevent assigning a lower or equal role, allowing a Guest to demote Administrators and Members and deny them project control. This vulnerability is fixed in 1.3.0.

Affected Software

1 affected component
Plane Plane<1.3.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Plane to a version that resolves this vulnerability.

    Fixed in 1.3.0

Event History

Oct 5, 2026
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any authenticated member of an affected project can exploit it, including a user assigned the lowest GUEST role. The attacker needs access to the target project but does not need administrator privileges or user interaction.

2

What is the practical impact of exploitation?

A Guest can change other project members to a lower or equal role, including demoting Administrators and Members. This can remove their project control and disrupt project administration.

3

Are patched versions available?

Yes. The issue is fixed in Plane 1.3.0; versions prior to 1.3.0 are affected.

4

What can be done if upgrading is not immediately possible?

Limit project membership to trusted users and remove unnecessary Guest access, since any project member can perform the vulnerable role update. Review project roles and restore any Administrators or Members that have been unexpectedly demoted.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203