PT-2026-106057 · Plane · Plane
CVE-2026-104978
·
Published
2026-10-05
·
Updated
2026-10-05
CVSS v3.1
8.2
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Plane versions prior to 1.4.0
Description
An authentication bypass exists where the project invitation list endpoint is accessible to any authenticated user who possesses the workspace slug and project ID. Additionally, the public project invitation join endpoint accepts invitations based solely on a submitted email address. If a pending invitation is sent to an email address not yet registered with the system, an attacker can enumerate the invitation, register an account using that email without mailbox verification, and accept the invitation to gain unauthorized access to the target workspace and project.
Recommendations
Update to version 1.4.0.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Plane