User Account Vulnerability in Plane Project Management Tool by MakePlane
CVE-2026-105640
9.1CRITICAL
What is CVE-2026-105640?
The Plane project management tool contains a vulnerability that occurs due to inadequate verification of email addresses returned by Gitea and self-managed GitLab OAuth deployments. This flaw allows an attacker to associate an unverified email address with a victim’s existing account, facilitating unauthorized access without needing the victim's password. The vulnerability has been addressed in version 1.4.0, where proper verification measures have been implemented to enhance account security. Notably, providers like GitHub and Google are not affected, as they ensure email addresses are verified before relaying them.
Affected Version(s)
plane < 1.4.0
