Medium severity5.4NVD Advisory· Published Oct 5, 2026· Updated Oct 5, 2026
CVE-2026-104893
CVE-2026-104893
Description
Plane is an open-source project management tool. Prior to 1.4.0, GET /api/users/api-tokens/ allows an authenticated user to retrieve API-token records, while PATCH /api/users/api-tokens/{token_id}/ allows the user to modify the token's allowed_rate_limit field without server-side validation or a maximum value. A user can raise the limit arbitrarily and bypass intended API rate-limiting controls, enabling high-volume automated requests, backend resource abuse, and possible resource exhaustion. This issue is fixed in 1.4.0.
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.