CVE-2026-104974
Deferred Deferred - Pending Action

Authentication Bypass in Plane Project Management Tool

Vulnerability report for CVE-2026-104974, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Plane is an open-source project management tool. Prior to 1.4.0, a user whose account has been deactivated by setting is_active=False can still log in with existing credentials. Successful authentication silently changes is_active back to True, reactivating the account without notifying the administrator. This issue is fixed in 1.4.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
makeplane plane < 1.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Plane (versions <= 1.3.1) allows deactivated user accounts to bypass deactivation. When an admin sets is_active=False to deactivate an account, the user can still log in. Upon successful login, the system silently reactivates the account by resetting is_active=True without notifying the administrator. This occurs because the authentication flow does not check the is_active flag before granting access.

Detection Guidance

To detect this vulnerability, check Plane application logs for successful logins by users who were previously deactivated. Look for accounts where is_active was set to false but later changed to true without admin intervention. Review authentication flow logs for the save_user_data() function triggering is_active=True unconditionally.

Impact Analysis

This vulnerability undermines account management by allowing reactivation of deactivated accounts without admin knowledge. Compromised or ex-employee accounts could regain access simply by logging in. It also enables unauthorized access to sensitive data or system functions if deactivated accounts are reactivated, potentially violating confidentiality and integrity.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA by allowing unauthorized access to personal or health data. GDPR requires proper account deactivation and data protection, while HIPAA mandates strict access controls. The silent reactivation of deactivated accounts violates these requirements by enabling unauthorized access to sensitive information.

Mitigation Strategies
  • Upgrade Plane to version 1.4.0 or later to apply the security fix.
  • Audit all user accounts for unexpected reactivations by checking is_active status changes in logs.
  • Review admin logs for any unauthorized account reactivations and revoke access for suspicious accounts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104974. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart