External risk intelligence

Plane Project Management Invitation Token Disclosure.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-105639

Plane is an open-source project management application. Such tools are commonly deployed as internet-facing web applications to facilitate collaboration among distributed teams and external stakeholders, making the web interface and associated API endpoints reachable from the public internet in standard deployment patterns.

Information Disclosure

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability impacts Plane, an open-source project management tool, allowing unauthenticated attackers to gain unauthorized access to sensitive information and potentially join workspaces by exploiting a flaw in the signup and invitation process. The issue arises because the system creates user accounts and exposes invitation tokens without proper ownership verification, which could enable malicious actors to impersonate users and join their projects.

  • Unverified signups can lead to unauthorized workspace access.
  • Confirms exposure of sensitive project invitations.
  • Verify relevance and exposure within your environment.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can register an account with a target's email address, then use that account to enumerate and accept pending workspace invitations intended for the target. This allows the attacker to join the target's workspace with the invited role, gaining access to their projects and data.

  • Attacker can register with any email.
  • Enumerates pending invitations via API.
  • Gains unauthorized workspace access.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker could exploit this vulnerability by registering an account with a target's email address, then enumerating and accepting pending workspace invitations as that target. This could lead to unauthorized access to project management data and services.

  • Project management data.
  • Email registration and invitation enumeration.
  • Unauthorized workspace access.

Operational Fix

Recommended remediation, mitigation, and detection steps

Determine ownership and scope by first identifying all Plane instances, assessing their exposure and business criticality, and confirming the responsible team or individual. Once identified, prioritize remediation actions based on risk, which may involve coordinating with the vendor or planning for an upgrade during a maintenance window.

  • Application owners should address this issue.
  • Verify external accessibility and business criticality.
  • Plan upgrade or risk reduction strategies.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Plane?

Plane is an open-source project management platform designed to help teams track tasks and organize workflows. It is typically deployed as a web application, often hosted to allow distributed team members and external partners to collaborate on projects directly through a shared interface.

How does CVE-2026-105639 affect security?

This issue involves Improper Authentication (CWE-287) and Exposure of Sensitive Information (CWE-200). The application fails to verify if a user actually owns the email address they use to sign up. Because the system subsequently allows any authenticated user to view pending workspace invitations tied to their email, an attacker can use a fake account to intercept and claim invitations intended for someone else.

What triggers this vulnerability?

An attacker triggers this by signing up for a new Plane account using a target user's email address. Once the attacker is logged in with this unverified account, they can query the API to list invitations associated with that email. This bug does not require any pre-existing account access or prior knowledge of the target's password; it relies entirely on the lack of email verification during the signup flow.

Who should prioritize CVE-2026-105639?

Organizations running Plane should prioritize this if their instance is reachable over the internet. According to Halo Surface Signal, these tools are frequently exposed publicly to support remote collaboration. If your instance is internet-facing, it is accessible to unauthorized actors, significantly increasing the likelihood that this flaw could be leveraged to gain unauthorized workspace access.

How do I secure my Plane instance?

The primary response is to update your Plane software to version 1.4.0 or later, where this invitation process has been corrected. Before applying the update, identify all instances within your environment to understand which systems are impacted. If an immediate upgrade is not possible, evaluate if you can restrict network access to the application until the patch is successfully deployed.

References