PT-2026-106087 · Plane+2 · Plane+2
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Plane versions prior to 1.4.0
Description
Plane trusts email addresses returned by Gitea OAuth and self-managed GitLab OAuth deployments where email confirmation is disabled, without verifying that the provider authenticated ownership of the address. An attacker can set an OAuth identity's unverified provider email to a victim's address, which the system matches directly to the victim's existing local account. This allows an attacker to log in to the victim's account without knowing the password.
Recommendations
Update to version 1.4.0.
Exploit
Fix
Authentication Bypass by Spoofing
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitlab
Gitea
Plane