OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-105638

CRITICAL · CVSS 9.1 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-05 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The Plane project management tool is vulnerable due to its implementation of a six-digit numeric OTP for email login, which offers insufficient entropy and lacks mechanisms to limit failed login attempts. This flaw allows attackers to exploit the absence of rate limiting, potentially enabling brute-force attacks to gain unauthorized access. Organizations using versions prior to 1.4.0 should prioritize upgrading to mitigate the risk of credential compromise.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-105638
Severity
CRITICAL
CVSS
9.1
EPSS
N/A

Original NVD Description

Plane is an open-source project management tool. Prior to 1.4.0, Plane's magic-code email login uses a six-digit numeric OTP with approximately 20 bits of entropy. The verifier has no per-code failed-attempt counter, and an incorrect code does not increment a counter, invalidate the Redis entry, or lock the email address. The verifier extends django.views.View rather than DRF's APIView, so the configured AnonRateThrottle limit does not apply. The middleware stack also contains no Django-level rate limiter such as django-ratelimit, django-axes, or an IP-throttling middleware. This vulnerability is fixed in 1.4.0.