Open-Source Project Management Tool Vulnerability in Plane by Makeplane
CVE-2026-104978

8.2HIGH

Key Information:

Vendor

Makeplane

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-104978?

The Plane project management tool has a security flaw where the project invitation list can be accessed by any authenticated user who knows the workspace slug and project ID. Additionally, the public project invitation join endpoint permits an invitation based solely on a provided email address. An attacker can leverage this by enumerating invitations aimed at unregistered email addresses, allowing them to create an account using the invitation email without verifying access to that mailbox. This results in the unauthorized account being added to the specified workspace and project. The issue has been addressed in version 1.4.0.

Affected Version(s)

plane < 1.4.0

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.