PT-2026-106088 · Git+1 · Plane

·

CVE-2026-105641

·

Published

2026-10-05

·

Updated

2026-10-05

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Plane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and deployments/cli/community/ manifests provide fixed, publicly known SECRET KEY and LIVE SERVER SECRET KEY defaults that remain active when operators do not override them. The top-level setup.sh randomizes secrets only for the development Docker Compose path, leaving unchanged aio and cli community deployments with shared production secrets. Knowledge of SECRET KEY enables attackers to forge Django-signed values and compromise accounts or sessions. Knowledge of LIVE SERVER SECRET KEY bypasses live-service authentication on unchanged community deployments. This issue is fixed in 1.4.0.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105641

Affected Products

Plane