CVE-2026-105639

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Plane is an open-source project management tool. Prior to 1.4.0, Plane's signup flow creates a logged-in User row for any submitted email without an out-of-band ownership check, while User.email is unique=True. The authenticated user can call GET /api/users/me/workspaces/invitations/, which returns each WorkspaceMemberInvite whose email matches request.user.email. WorkSpaceMemberInviteSerializer uses fields = "all", exposing the token that protects the invitation join endpoint. An unauthenticated attacker who knows a target's email can register an account using that address, enumerate pending invitations, and accept an invitation as the target, joining a workspace at the invited role. The term pre-auth describes the attacker's initial state: the attacker has no credential before signup, while the enumeration and join requests use the session created by that signup. This issue is fixed in 1.4.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-287CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-05: 110-05
Referenced assets1 URL
By indicator
Full discourse1 post
  • The Hacker Wire@TheHackerWire

    🚨 CVE-2026-105639 (CVSS 9.8 Critical) A critical flaw in Plane prior to 1.4.0 lets unauthenticated attackers register victim emails without verification, enumerate pending workspace invites, and hijack member access. https://www.thehackerwire.com/vulnerability/CVE-2026-105639/ https://t.co/kfI8Ozt6iq

    0000029
    175 followersView on X

Explore more