External risk intelligence

Plane Numeric OTP Bypass Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-105638

Plane is a project management web application. Such applications are commonly deployed as internet-facing services to facilitate access for distributed teams, and the vulnerability specifically affects the email-based authentication login flow, which is a core, externally reachable web component.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability exists in the Plane project management tool, specifically within its email login process. This flaw allows for a brute-force attack on one-time passcodes, potentially leading to unauthorized access to user accounts and sensitive project data. While the tool is open-source, its use in managing projects makes this a concern for any organization relying on it for operations.

  • Weak login security allows account takeover.
  • Affects core authentication of a project tool.
  • Confirm relevance and exposure to projects.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by repeatedly attempting to guess a six-digit numeric code used for email login. Because the system does not limit failed login attempts or block IP addresses, an attacker can automate this guessing process to gain unauthorized access to user accounts. This could allow them to view and modify project management data.

  • No rate limiting on login attempts.
  • Six-digit code guessing is possible.
  • Unauthorized access to sensitive data.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to bypass email-based login protections in Plane, potentially enabling unauthorized access to project management data. This could occur when the application is configured to use the affected email login feature without additional security measures.

  • Unauthorized access to project data.
  • Brute-force attacks on OTP codes.
  • Compromise of sensitive project information.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts the authentication mechanism of the Plane project management tool, likely managed by application owners or platform teams responsible for its deployment and operation. The initial focus should be on identifying all instances of Plane, assessing their exposure and criticality, and confirming the accountable owner for remediation.

  • Identify Plane instances and assess risk.
  • Confirm the accountable application owner.
  • Plan remediation or risk reduction.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Plane and how is it used?

Plane is an open-source project management platform. Teams use it to organize work, track project progress, and manage tasks. Because it serves as a central hub for organizational data, it is typically deployed as a web application that must be accessed by various team members, sometimes across distributed environments.

What does CVE-2026-105638 mean for my security?

This vulnerability is classified as CWE-307: Improper Restriction of Excessive Authentication Attempts. It means the software does not properly limit how many times a user can guess a one-time passcode. Because the verification system lacks rate-limiting or lockouts, an attacker can systematically guess the six-digit code until they successfully gain unauthorized access to an account.

How can an attacker trigger this vulnerability?

An attacker initiates the vulnerability by targeting the email login flow, specifically the six-digit numeric OTP request. The attack succeeds through automation, repeatedly guessing codes without being stopped. Crucially, the vulnerability is not triggered by standard, successful user logins; it is specifically the absence of security controls—like IP-throttling or failed-attempt counters—that allows the automated guessing process to proceed unchecked.

Do I need to worry if my Plane instance is internal?

Halo Surface Signal indicates that Plane instances are commonly deployed as internet-facing services to support distributed teams. If your instance is reachable from the internet, the risk is higher because the authentication endpoint is exposed. Even if internal, evaluate who has network access, as the vulnerability affects a core, externally reachable web component regardless of its specific placement.

When should I update my Plane installation?

You should plan to update to version 1.4.0 or later immediately. This update addresses the missing rate-limiting logic within the email authentication process. As a first step, verify your current version, identify all active instances in your environment, and prioritize patching those that handle sensitive project data to mitigate the risk of unauthorized account access.

References