CVE-2026-104892EPSS p14.6%

CVE-2026-104892CVE-2026-104892

Description

Plane is an open-source project management tool. Prior to 1.4.0, aPITokenLogMiddleware logs API keys in plaintext. This allows someone with low privileges to steal user API keys and further escalate their privileges. This issue is fixed in 1.4.0.

Scoring

EPSS0.25% probability of exploitation · percentile 14.6% · 2026-10-10T12:00:23Z
Last modified2026-10-05
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.