CRITICAL
9.1 CVE-2026-105640 Published 5 Oct 2026
Plane Project Management Tool OAuth Account Takeover Vulnerability
Worried this affects your website?
Plane, an open-source project management tool, had an account takeover flaw prior to version 1.4.0. The application trusted email addresses returned by Gitea OAuth and by self-managed GitLab OAuth deployments where email confirmation is disabled, without verifying that the provider authenticated ownership of the address.
An attacker could set an OAuth identity's unverified provider email to a victim's address, which Plane matched directly to the victim's existing local account. The attacker could then log in to the victim's Plane account without knowing the victim's password.
Vulnerability type: OAuth email verification bypass leading to account takeover.
- Affected versions: prior to 1.4.0
- Fixed in: 1.4.0
- Not affected: GitHub, GitLab.com, and Google, because those providers return verified email addresses
Reference: CVE-2026-105640 on NVD
← Back to Security News