CVE-2026-105634: Plane: Privilege Escalation: Project Guest Can Demote Admin/Member Roles
Plane is an open-source project management tool. Prior to 1.3.0, the ProjectMemberViewSet.partialupdate method allows any project member, including a user with the lowest GUEST role, to modify another project member's role. The authorization check prevents assigning a role higher than the requester's role but does not prevent assigning a lower or equal role, allowing a Guest to demote Administrators and Members and deny them project control. This vulnerability is fixed in 1.3.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Planeto a version that resolves this vulnerability.Fixed in 1.3.0
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated member of an affected project can exploit it, including a user assigned the lowest GUEST role. The attacker needs access to the target project but does not need administrator privileges or user interaction.
What is the practical impact of exploitation?
A Guest can change other project members to a lower or equal role, including demoting Administrators and Members. This can remove their project control and disrupt project administration.
Are patched versions available?
Yes. The issue is fixed in Plane 1.3.0; versions prior to 1.3.0 are affected.
What can be done if upgrading is not immediately possible?
Limit project membership to trusted users and remove unnecessary Guest access, since any project member can perform the vulnerable role update. Review project roles and restore any Administrators or Members that have been unexpectedly demoted.