OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-105640

CRITICAL · CVSS 9.1 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-05 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The vulnerability affects Plane, an open-source project management tool, which improperly trusts unverified email addresses from Gitea and self-managed GitLab OAuth deployments when email confirmation is disabled. This flaw allows an attacker to exploit the OAuth identity to log into a victim's Plane account without needing their password, posing a critical security risk. Organizations using Plane versions prior to 1.4.0 should prioritize immediate updates to mitigate this authentication bypass vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-105640
Severity
CRITICAL
CVSS
9.1
EPSS
N/A
GitLab GitHub

Original NVD Description

Plane is an open-source project management tool. Prior to 1.4.0, Plane trusts email addresses returned by Gitea OAuth and by self-managed GitLab OAuth deployments where email confirmation is disabled, without verifying that the provider authenticated ownership of the address. An attacker can set an OAuth identity's unverified provider email to a victim's address, which Plane matches directly to the victim's existing local account. The attacker can then log in to the victim's Plane account without knowing the victim's password. GitHub, GitLab.com, and Google are not affected because those providers return verified email addresses. This issue is fixed in 1.4.0.