{"id":"CVE-2026-104892","title":"Plane is an open-source project management tool","summary":"Plane is an open-source project management tool. Prior to 1.4.0, aPITokenLogMiddleware logs API keys in plaintext. This allows someone with low privileges to steal user API keys and further escalate their privileges. This issue is fixed …","severity":"high","cvss":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N","cwe":["CWE-256"],"vendor":"makeplane","product":"plane","affected":["plane < 1.4.0"],"published":"2026-10-05","updated":"2026-10-05","sourceUpdated":"2026-10-05T17:17:10.543","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-104892","references":[{"url":"https://github.com/makeplane/plane/commit/edf247541301e482f2688c63481464b671ec579d","label":"security-advisories@github.com"},{"url":"https://github.com/makeplane/plane/pull/9148","label":"security-advisories@github.com"},{"url":"https://github.com/makeplane/plane/releases/tag/v1.4.0","label":"security-advisories@github.com"},{"url":"https://github.com/makeplane/plane/security/advisories/GHSA-r5p8-cj3q-38cc","label":"security-advisories@github.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-10-05T16:21:22.547515Z"},"cvssSource":"cna","ingestedAt":"2026-10-05T16:25:58.410Z","slug":"CVE-2026-104892","body":"## Overview\n\nPlane is an open-source project management tool. Prior to 1.4.0, aPITokenLogMiddleware logs API keys in plaintext. This allows someone with low privileges to steal user API keys and further escalate their privileges. This issue is fixed in 1.4.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":47.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}