CVE-2026-105639
Deferred Deferred - Pending Action

Plane Pre-Auth Workspace Invitation Token Exposure

Vulnerability report for CVE-2026-105639, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Plane is an open-source project management tool. Prior to 1.4.0, Plane's signup flow creates a logged-in User row for any submitted email without an out-of-band ownership check, while User.email is unique=True. The authenticated user can call GET /api/users/me/workspaces/invitations/, which returns each WorkspaceMemberInvite whose email matches request.user.email. WorkSpaceMemberInviteSerializer uses fields = "all", exposing the token that protects the invitation join endpoint. An unauthenticated attacker who knows a target's email can register an account using that address, enumerate pending invitations, and accept an invitation as the target, joining a workspace at the invited role. The term pre-auth describes the attacker's initial state: the attacker has no credential before signup, while the enumeration and join requests use the session created by that signup. This issue is fixed in 1.4.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
makeplane plane < 1.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Plane (CVE-2026-105639) allows an unauthenticated attacker to hijack workspace invitations. The issue occurs because Plane creates a logged-in user account for any submitted email without verifying ownership. An attacker can register using a target's email, then enumerate pending invitations for that email via an API endpoint. The endpoint exposes invitation tokens, which the attacker can use to join the workspace at the invited role, potentially gaining admin access.

Detection Guidance

Check Plane versions prior to 1.4.0 for vulnerable endpoints. Monitor logs for repeated signup attempts with target emails. Inspect API responses for /api/users/me/workspaces/invitations/ to see if tokens are exposed. Use network traffic analysis to detect unauthorized workspace joins.

Impact Analysis

An attacker could gain unauthorized access to your workspace, allowing them to view sensitive data, modify settings, add or remove members, or delete projects. If the invitation was for an admin role, the attacker could take full control of the workspace. This bypasses authentication entirely, as the attacker starts with no credentials.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR's data protection principles and HIPAA's security requirements. It may result in confidentiality breaches, unauthorized data exposure, or integrity compromises, all of which are critical compliance failures.

Mitigation Strategies

Upgrade Plane to version 1.4.0 or later immediately. Disable public signup if not required. Implement email verification before account creation. Restrict access to invitation endpoints and audit workspace memberships for unauthorized joins.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105639. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart