CVE-2026-105632
Plane: Broken Access Control - joinProject GraphQL mutation allows self-join into private (secret) projects
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Plane is an open-source project management tool. Prior to 1.4.0, the GraphQL joinProject mutation lets any workspace member add themselves to any project in that workspace including network=0 (secret/private) projects they were never invited to and grants them a full Member role (read + write). The resolver checks only workspace-level membership/role and never checks the target project's visibility (network). This collapses project-level tenant isolation within a workspace: a low-privilege member can read and modify confidential data in every private project. This issue is fixed in 1.4.0.
| CWE | CWE-284 |
| Vendor | makeplane |
| Product | plane |
| Published | Oct 5, 2026 |
| Last Updated | Oct 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for makeplane plane
Be the first to know when new unknown vulnerabilities affecting makeplane plane are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
makeplane / plane
< 1.4.0
References
github.com: https://github.com/makeplane/plane/security/advisories/GHSA-45hc-q4mw-jhxm github.com: https://github.com/makeplane/plane/pull/9333 github.com: https://github.com/makeplane/plane/commit/e1ef42023ab66b5e722a8750e1bc5ba0d413a3ee github.com: https://github.com/makeplane/plane/releases/tag/v1.4.0