User Account Vulnerability in Plane Project Management Tool by MakePlane
CVE-2026-105640

9.1CRITICAL

Key Information:

Vendor

Makeplane

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105640?

The Plane project management tool contains a vulnerability that occurs due to inadequate verification of email addresses returned by Gitea and self-managed GitLab OAuth deployments. This flaw allows an attacker to associate an unverified email address with a victim’s existing account, facilitating unauthorized access without needing the victim's password. The vulnerability has been addressed in version 1.4.0, where proper verification measures have been implemented to enhance account security. Notably, providers like GitHub and Google are not affected, as they ensure email addresses are verified before relaying them.

Affected Version(s)

plane < 1.4.0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.