CVE-2026-105632EPSS p22.2%
CVE-2026-105632CVE-2026-105632
Description
Plane is an open-source project management tool. Prior to 1.4.0, the GraphQL joinProject mutation lets any workspace member add themselves to any project in that workspace including network=0 (secret/private) projects they were never invited to and grants them a full Member role (read + write). The resolver checks only workspace-level membership/role and never checks the target project's visibility (network). This collapses project-level tenant isolation within a workspace: a low-privilege member can read and modify confidential data in every private project. This issue is fixed in 1.4.0.
Scoring
| EPSS | 0.31% probability of exploitation · percentile 22.2% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-05 |