Mmastodon TechnologyCybersecurity first seen 14 h ago, last 14 h ago, peak #12
High-severity flaw disclosed in Plane project management tool
Original: 🟠 CVE-2026-105634 - High (8.1) Plane is an open-source project management tool. Prior to 1.3.0, the ProjectMemberViewSet
A high-severity vulnerability, CVE-2026-105634, has been disclosed in Plane, an open-source project management tool. Versions prior to 1.3.0 allow any project member, including users with the lowest GUEST role, to change another member's role through the ProjectMemberViewSet partial_update endpoint due to missing authorization checks. Users are advised to upgrade to 1.3.0 or later.
Why now: Security teams are discussing the newly published flaw so they can patch exposed Plane instances before it is exploited.
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/1150965