CVE-2026-105640
Deferred Deferred - Pending Action

Authentication Bypass in Plane via OAuth Email Spoofing

Vulnerability report for CVE-2026-105640, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Plane is an open-source project management tool. Prior to 1.4.0, Plane trusts email addresses returned by Gitea OAuth and by self-managed GitLab OAuth deployments where email confirmation is disabled, without verifying that the provider authenticated ownership of the address. An attacker can set an OAuth identity's unverified provider email to a victim's address, which Plane matches directly to the victim's existing local account. The attacker can then log in to the victim's Plane account without knowing the victim's password. GitHub, GitLab.com, and Google are not affected because those providers return verified email addresses. This issue is fixed in 1.4.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
makeplane plane < 1.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-290 This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105640 is a critical vulnerability in Plane, an open-source project management tool. It allows attackers to take over a victim's account by exploiting unverified email addresses returned by OAuth providers like Gitea or self-managed GitLab (where email confirmation is disabled). Plane matches accounts by email without verifying if the email is confirmed by the provider. An attacker controlling such a provider can set the victim's email as unverified in OAuth responses, allowing them to log into the victim's Plane account without a password.

Detection Guidance

To detect this vulnerability, check Plane application logs for OAuth authentication attempts with unverified emails. Look for error codes like OAUTH_PROVIDER_UNVERIFIED_EMAIL (5124) or failed logins matching victim accounts. Verify if your Plane instance uses versions prior to 1.4.0 and if OAuth providers (Gitea, GitLab) have email confirmation disabled.

Impact Analysis

If you use Plane versions prior to 1.4.0, an attacker could gain full access to your Plane account, including workspaces, projects, and sensitive data. This could lead to data theft, unauthorized modifications, or disruption of your projects. The attack requires no prior privileges or user interaction and is executed remotely over the network.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection principles and HIPAA's security requirements for protected health information. It may result in data breaches, non-compliance penalties, and loss of trust. Organizations using affected Plane versions must address this flaw to maintain compliance.

Mitigation Strategies

Upgrade Plane to version 1.4.0 or later. Ensure OAuth providers (GitHub, GitLab, Google, Gitea) enforce verified emails. Disable OAuth logins for Gitea or self-managed GitLab instances with email confirmation disabled. Monitor for unauthorized access attempts and review account activity for suspicious logins.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105640. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart