Sceawere
Vulnerability Detail
CVE-2026-104955UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Plane Authorization Bypass Privilege Escalation
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.4
- Creation Date
- 2h ago
- Vendor
- makeplane
- Product
- plane
- Attack Type
- CWE-269: Improper Privilege Management
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Plane is an open-source project management tool. Prior to 1.4.0, a Project Member with role 15 can send a PATCH request to the project-member update endpoint at /api/workspaces/{workspace_slug}/projects/{project_id}/members/{member_pk}/ to change another user's project role. The role-update logic blocks only a new role higher than the requester's role, so assigning the equal Member role bypasses the insufficient validation and promotes a Project Guest with role 5 to Member without Project Admin approval. This unauthorized promotion grants the guest the additional project capabilities associated with the Member role and allows a regular member to bypass project governance controls. This issue is fixed in 1.4.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.4",
"pubDate": "2026-10-05T17:17:10.970Z",
"pubdate": "2026-10-05T17:17:10.970Z",
"executiveSummary": "The vulnerability is an Improper Access Control flaw within the Plane project management tool that permits unauthorized privilege escalation. Prior to version 1.4.0, a authenticated Project Member can exploit an insufficient validation logic in the project-member update API endpoint. This flaw allows a user with role 15 to modify the permissions of other project participants, specifically enabling the promotion of a Project Guest (role 5) to the Member role (role 15).\nThe impact of this vulnerability involves the bypass of project governance and administrative controls, granting unauthorized users elevated capabilities within the application. This escalation can lead to unauthorized access to sensitive project data or functionalities restricted to members. Exploitation requires the attacker to possess an existing, authenticated, and valid project membership. The vulnerability is categorized as a failure in server-side authorization checks, where the logic incorrectly permits role updates that are equal to the requester's level, bypassing the intended hierarchical restrictions.",
"technicalDetails": "The root cause of this vulnerability lies in the server-side authorization logic governing the project-member update endpoint: /api/workspaces/{workspace_slug}/projects/{project_id}/members/{member_pk}/. The application utilizes a role-based access control (RBAC) mechanism where roles are represented by integer values (e.g., Guest=5, Member=15).\nThe validation logic implemented to prevent unauthorized role modifications incorrectly evaluates the requester's role against the target role. Specifically, the check only blocks attempts to assign a role higher than that of the requester. By failing to account for equal-level assignments, the check allows a user with role 15 to perform a PATCH request that modifies a role 5 user to role 15 without administrative intervention.\nThe attack flow proceeds as follows: 1) An authenticated user with role 15 identifies a target user with role 5. 2) The attacker crafts a malicious PATCH request directed at the project-member update endpoint. 3) The request includes a payload specifying the update of the target member's role to 15. 4) The server-side API receives the request and executes the update logic. Because the requested role (15) is not strictly greater than the requester's role (15), the validation logic fails to trigger a deny response. 5) The database record for the target member is updated, successfully escalating the target's privileges.\nThis vulnerability is present in versions of Plane prior to 1.4.0. The exploit requires the attacker to have an active session and membership within the specific project context, as the API validates the {workspace_slug}, {project_id}, and {member_pk} parameters. Post-exploitation, the elevated user inherits all functional capabilities associated with the Member role, effectively subverting administrative access controls. This vulnerability highlights a failure to implement strict 'Principle of Least Privilege' checks when handling role modification requests, allowing for horizontal and vertical privilege escalation scenarios within the project management lifecycle."
}