CRITICAL 9.1 CVE-2026-105638 Published 5 Oct 2026

Plane Project Management Tool OTP Brute-Force Vulnerability

Worried this affects your website?

Plane, an open-source project management tool, is affected by a magic-code OTP brute-force vulnerability before version 1.4.0.

Its magic-code email login uses a six-digit numeric OTP with approximately 20 bits of entropy. The verifier has no per-code failed-attempt counter or lockout mechanism.

  • An incorrect code does not increment a counter, invalidate the Redis entry, or lock the email address.
  • The verifier extends django.views.View rather than DRF's APIView, so the configured AnonRateThrottle limit does not apply.
  • The middleware stack has no Django-level rate limiter such as django-ratelimit, django-axes, or IP-throttling middleware.

This vulnerability is fixed in version 1.4.0.

Reference: CVE-2026-105638 on NVD

← Back to Security News