PT-2026-106057 · Plane · Plane

CVE-2026-104978

·

Published

2026-10-05

·

Updated

2026-10-05

CVSS v3.1

8.2

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Plane versions prior to 1.4.0
Description An authentication bypass exists where the project invitation list endpoint is accessible to any authenticated user who possesses the workspace slug and project ID. Additionally, the public project invitation join endpoint accepts invitations based solely on a submitted email address. If a pending invitation is sent to an email address not yet registered with the system, an attacker can enumerate the invitation, register an account using that email without mailbox verification, and accept the invitation to gain unauthorized access to the target workspace and project.
Recommendations Update to version 1.4.0.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-104978
GHSA-G36H-P63V-G9C7

Affected Products

Plane