CVE-2026-105634: CWE-269: Improper Privilege Management in makeplane plane
Description
Plane, an open-source project management tool, has a privilege management vulnerability prior to version 1.3.0. The flaw allows any project member, including those with the lowest GUEST role, to modify other members' roles. While the system prevents assigning roles higher than the requester's, it does not prevent assigning equal or lower roles, enabling a Guest to demote Administrators and Members, potentially disrupting project control. This issue is resolved in version 1.3.0.
CVSS v3.1
Score 8.1high
Affected software
makeplane
plane
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-105634 describes an improper privilege management vulnerability (CWE-269) in the Plane project management tool. Specifically, in versions before 1.3.0, the ProjectMemberViewSet.partial_update method allows any project member, including those with the GUEST role, to change the roles of other project members. The authorization logic restricts assigning roles higher than the requester's but fails to prevent assigning equal or lower roles. This permits a low-privilege user to demote higher-privilege users, such as Administrators and Members, thereby undermining project governance. The vulnerability is fixed in Plane version 1.3.0.
Potential Impact
An attacker with the lowest GUEST role can demote other project members, including Administrators and Members, reducing their privileges and potentially denying them control over the project. This can lead to disruption of project management and unauthorized changes in project roles. The vulnerability does not allow privilege escalation beyond the attacker's own role but enables privilege reduction of others, impacting integrity and availability of project management functions.
Mitigation Recommendations
This vulnerability is fixed in Plane version 1.3.0. Users should upgrade to version 1.3.0 or later to remediate the issue. No other mitigations are indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-10-05T16:40:39.611Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac3ed962cdf04f6562b655f
Added to database: 10/05/2026, 18:33:58 UTC
Last enriched: 10/05/2026, 18:48:59 UTC
Last updated: 10/05/2026, 21:08:08 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.