CRITICAL 9.1 CVE-2026-105640 Published 5 Oct 2026

Plane Project Management Tool OAuth Account Takeover Vulnerability

Worried this affects your website?

Plane, an open-source project management tool, had an account takeover flaw prior to version 1.4.0. The application trusted email addresses returned by Gitea OAuth and by self-managed GitLab OAuth deployments where email confirmation is disabled, without verifying that the provider authenticated ownership of the address.

An attacker could set an OAuth identity's unverified provider email to a victim's address, which Plane matched directly to the victim's existing local account. The attacker could then log in to the victim's Plane account without knowing the victim's password.

Vulnerability type: OAuth email verification bypass leading to account takeover.

  • Affected versions: prior to 1.4.0
  • Fixed in: 1.4.0
  • Not affected: GitHub, GitLab.com, and Google, because those providers return verified email addresses

Reference: CVE-2026-105640 on NVD

← Back to Security News