OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-105634

HIGH · CVSS 8.1 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-05 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The ProjectMemberViewSet.partial_update method in Plane, prior to version 1.3.0, allows users with the GUEST role to modify the roles of other project members, potentially demoting Administrators and Members. This flaw can severely impact project control and security, making it critical for organizations using this project management tool to upgrade to version 1.3.0 immediately to mitigate the risk. All users of the affected versions should prioritize this update to protect their project integrity.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-105634
Severity
HIGH
CVSS
8.1
EPSS
0.29%

Original NVD Description

Plane is an open-source project management tool. Prior to 1.3.0, the ProjectMemberViewSet.partial_update method allows any project member, including a user with the lowest GUEST role, to modify another project member's role. The authorization check prevents assigning a role higher than the requester's role but does not prevent assigning a lower or equal role, allowing a Guest to demote Administrators and Members and deny them project control. This vulnerability is fixed in 1.3.0.