CVE-2026-105638
Deferred Deferred - Pending Action

Six-Digit OTP Brute Force in Plane

Vulnerability report for CVE-2026-105638, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Plane is an open-source project management tool. Prior to 1.4.0, Plane's magic-code email login uses a six-digit numeric OTP with approximately 20 bits of entropy. The verifier has no per-code failed-attempt counter, and an incorrect code does not increment a counter, invalidate the Redis entry, or lock the email address. The verifier extends django.views.View rather than DRF's APIView, so the configured AnonRateThrottle limit does not apply. The middleware stack also contains no Django-level rate limiter such as django-ratelimit, django-axes, or an IP-throttling middleware. This vulnerability is fixed in 1.4.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
makeplane plane < 1.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-307 The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105638 is a brute-force vulnerability in Plane's magic-code email login system. It allows attackers to bypass rate limits and attempt all 900,000 possible 6-digit OTP codes without restrictions. The verifier lacks a failed-attempt counter, so incorrect codes do not trigger locks or invalidate tokens. The endpoint uses Django views instead of DRF APIView, disabling rate limiting. This enables pre-authentication account takeover if the victim's email is known.

Detection Guidance

To detect brute-force attempts targeting the Plane magic-code login, monitor for repeated requests to the magic-code verification endpoint (e.g., /api/magic-sign-in/verify/) from the same IP address. Check Redis for high failure counts on magic-code keys or unusual patterns of rapid token regeneration. Use Django logs to identify excessive failed attempts or rate-limit violations.

Impact Analysis

An attacker can gain unauthorized access to your Plane account by brute-forcing the 6-digit OTP. This requires only knowledge of your email address and no additional access. The attack can succeed within hours at 50 requests per second. Once exploited, the attacker can take over your account, access sensitive data, or perform actions on your behalf.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection and access control. GDPR mandates strong authentication and protection against unauthorized access. HIPAA requires safeguards to ensure data confidentiality and integrity. The lack of rate limiting and brute-force protection could lead to unauthorized data exposure, violating these standards.

Mitigation Strategies
  • Upgrade Plane to version 1.4.0 or later to apply the official fix.
  • Implement a per-token attempt counter in Redis to track failed verifications and invalidate tokens after 5 failed attempts.
  • Apply rate limiting to magic-link endpoints using Django's AuthenticationThrottle (default 10 requests per minute per IP).
  • Ensure magic-code endpoints use DRF APIView or equivalent rate-limiting middleware to enforce throttling.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105638. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart