Authentication Bypass in Plane Project Management Tool
CVE-2026-104974
8.1HIGH
What is CVE-2026-104974?
The Plane project management tool has a vulnerability that allows a deactivated user account to log in using existing credentials. When a user's account is set to inactive, they should not be able to access the system. However, prior to version 1.4.0, these accounts could be reactivated silently upon successful login, without notifying the administrator. This flaw poses significant risks to user account management and security. The issue was resolved in version 1.4.0, which prevents deactivated accounts from logging in.
Affected Version(s)
plane < 1.4.0
