CVE-2026-105634 - Plane: Privilege Escalation: Project Guest Can Demote Admin/Member Roles
CVE ID :CVE-2026-105634 Published : Oct. 5, 2026, 6 p.m. | 1 hour, 27 minutes ago Description :Plane is an open-source project management tool. Prior to 1.3.0, the ProjectMemberViewSet.partial_update method allows any project member, including a user with the lowest GUEST role, to modify...