CVE-2026-105632 - Plane: Broken Access Control - joinProject GraphQL mutation allows self-join into private (secret) projects
CVE ID :CVE-2026-105632 Published : Oct. 5, 2026, 6:17 p.m. | 1 hour, 10 minutes ago Description :Plane is an open-source project management tool. Prior to 1.4.0, the GraphQL joinProject mutation lets any workspace member add themselves to any project in that workspace including network=0...