CVE-2026-105640

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Plane is an open-source project management tool. Prior to 1.4.0, Plane trusts email addresses returned by Gitea OAuth and by self-managed GitLab OAuth deployments where email confirmation is disabled, without verifying that the provider authenticated ownership of the address. An attacker can set an OAuth identity's unverified provider email to a victim's address, which Plane matches directly to the victim's existing local account. The attacker can then log in to the victim's Plane account without knowing the victim's password. GitHub, GitLab.com, and Google are not affected because those providers return verified email addresses. This issue is fixed in 1.4.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-290

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-05: 110-05
Referenced assets1 URL
By indicator
Full discourse1 post
  • The Hacker Wire@TheHackerWire

    🚨 CVE-2026-105640 (CVSS 9.1 Critical) Plane prior to 1.4.0 blindly trusts unverified emails from Gitea and self-managed GitLab OAuth, allowing attackers to link arbitrary accounts and bypass authentication. https://www.thehackerwire.com/vulnerability/CVE-2026-105640/ https://t.co/InYb8Ho7Xm

    0000024
    175 followersView on X

Explore more