Sceawere

Vulnerability Detail

CVE-2026-104893UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Plane API Rate-Limit Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
2h ago
Vendor
makeplane
Product
plane
Attack Type
CWE-770: Allocation of Resources Without Limits or Throttling
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Plane is an open-source project management tool. Prior to 1.4.0, GET /api/users/api-tokens/ allows an authenticated user to retrieve API-token records, while PATCH /api/users/api-tokens/{token_id}/ allows the user to modify the token's allowed_rate_limit field without server-side validation or a maximum value. A user can raise the limit arbitrarily and bypass intended API rate-limiting controls, enabling high-volume automated requests, backend resource abuse, and possible resource exhaustion. This issue is fixed in 1.4.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-10-05T17:17:10.650Z",
  "pubdate": "2026-10-05T17:17:10.650Z",
  "executiveSummary": "A broken access control vulnerability exists in Plane versions prior to 1.4.0, specifically regarding the handling of API token configurations.\nThe vulnerability manifests as an Improper Authorization flaw, allowing authenticated users to modify the 'allowed_rate_limit' property of their own API tokens via the PATCH /api/users/api-tokens/{token_id}/ endpoint.\nBecause the application lacks server-side validation or maximum value enforcement for this field, attackers can arbitrarily escalate their permitted request quotas.\nThis exploit effectively bypasses established platform rate-limiting controls, facilitating unauthorized high-volume automated traffic.\nThe potential impact includes severe backend resource abuse, degradation of system performance, and potential service denial through resource exhaustion.\nExploitation requires the attacker to possess a valid, authenticated user account within the Plane environment. No administrative privileges are required, as users are permitted to manage their own tokens, but the lack of server-side constraints transforms this management capability into a security flaw.\nThis represents a significant risk to the availability and integrity of the backend API infrastructure.",
  "technicalDetails": "The vulnerability resides within the user API token management logic of the Plane application, specifically affecting the processing of PATCH requests to the /api/users/api-tokens/{token_id}/ endpoint.\nRoot Cause: The application implements insufficient input validation on the 'allowed_rate_limit' field during the update process. The backend fails to enforce a maximum threshold or sanity check on the integer value provided in the client request body.\nAttack Flow: An authenticated user initiates a GET request to /api/users/api-tokens/ to enumerate their existing token identifiers. Upon identifying a target {token_id}, the user performs a PATCH request to /api/users/api-tokens/{token_id}/, injecting an arbitrarily high integer value into the 'allowed_rate_limit' field.\nThe server-side component processes this request by persisting the user-supplied value directly into the database without sanitizing or capping it against a global or per-user policy limit.\nConsequences: Once the database is updated with the inflated limit, subsequent API calls authenticated with the modified token ignore or bypass the intended rate-limiting middleware.\nExploitation Method: An attacker can set the limit to an effectively infinite value, granting them the ability to bypass request throttling mechanisms. This behavior enables the execution of high-volume automated scripts that would otherwise be rejected or delayed by the platform.\nImpact: Post-exploitation, the attacker gains the capability to perform sustained, high-concurrency requests, which can be leveraged to scrape data at high velocity, perform brute-force attempts on other endpoints, or consume server resources (CPU, memory, database connections) to a degree that induces denial-of-service conditions for legitimate users.\nAffected Versions: All versions of Plane prior to 1.4.0.\nAuthentication/Privilege Requirements: The attacker must have an authenticated session. The vulnerability leverages the inherent design of the user-facing API management interface rather than requiring elevated permissions."
}
CVE-2026-104893: Plane API Rate-Limit Bypass (MEDIUM Severity, CVSS: 5.4) | Sceawere