CVE-2026-105634High· 8.1▾ TwilightPlane is an open-source project management tool. Prior to 1.3.0, the ProjectMemberViewSet.partial_update method allows any project member, including a user with the lowest GUEST role, to modify another project member's role. The authoriz…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Plane is an open-source project management tool. Prior to 1.3.0, the ProjectMemberViewSet.partial_update method allows any project member, including a user with the lowest GUEST role, to modify another project member's role. The authorization check prevents assigning a role higher than the requester's role but does not prevent assigning a lower or equal role, allowing a Guest to demote Administrators and Members and deny them project control. This vulnerability is fixed in 1.3.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-104955Medium· 5.4Plane is an open-source project management tool
CVE-2026-105635High· 7.4Plane is an open-source project management tool
CVE-2026-105636Critical· 9.9Plane is an open-source project management tool
CVE-2026-105637Critical· 9.6Plane is an open-source project management tool
CVE-2026-105638Critical· 9.1Plane is an open-source project management tool
CVE-2026-105639Critical· 9.8Plane is an open-source project management tool