OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-105635

HIGH · CVSS 7.4 EPSS 0.45% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-05 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The ProjectJoinEndpoint in versions prior to 1.4.0 of the Plane project management tool is vulnerable, allowing unauthenticated users to access sensitive ProjectMemberInvite information, including email addresses and invitation tokens. This flaw enables attackers to exploit the invitation system by registering accounts with invited emails and accepting invitations without proper authorization. Organizations using affected versions should prioritize updating to 1.4.0 to mitigate the risk of unauthorized access and potential account takeovers.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-105635
Severity
HIGH
CVSS
7.4
EPSS
0.45%

Original NVD Description

Plane is an open-source project management tool. Prior to 1.4.0, ProjectJoinEndpoint at GET /api/workspaces/{slug}/projects/{project_id}/join/{pk}/ uses permission_classes = [AllowAny] and returns the full ProjectMemberInvite record, including its email, token, and role, to unauthenticated callers. The corresponding POST endpoint checks only whether the submitted email matches project_invite.email and does not validate the invitation token. An attacker who knows the invitation UUID can discover the invited email, register an account with that email, and accept the invitation without receiving the original invite. This issue is fixed in 1.4.0.