External risk intelligence

Plane OAuth Account Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-105640

Plane is an open-source project management tool. Such applications are commonly deployed as web-based interfaces and collaboration platforms accessible to users over the network, making them frequent candidates for internet-facing or wide-area network deployments.

Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability exists in Plane, an open-source project management tool, which could allow an attacker to gain unauthorized access to user accounts. This occurs when the tool trusts email addresses from certain OAuth providers without proper verification, enabling an attacker to hijack an account by impersonating a victim's email address. While specific affected deployments are limited to those with disabled email confirmation for self-managed GitLab and Gitea OAuth, it's important to confirm relevance and exposure.

  • Unverified emails allow account takeovers.
  • Affects user account integrity and access.
  • Confirm if your Plane deployment is exposed.

Attack Path

How an attacker could exploit the issue

An attacker can impersonate a user by manipulating the email address associated with an OAuth login through a misconfigured Gitea or self-managed GitLab instance. This allows them to gain unauthorized access to a victim's Plane account without needing their password.

  • Unverified OAuth email address from Gitea/GitLab.
  • Attacker sets victim's email in OAuth provider.
  • Account takeover without password.

Live Threat

Current exploitation, exposure, and threat context

When Plane is configured with Gitea OAuth or self-managed GitLab OAuth with disabled email confirmation, an attacker could impersonate a user. This occurs when an attacker manipulates the OAuth provider's email to match a victim's existing local account, allowing the attacker to log in without the victim's password.

  • User account access.
  • Unverified email identity linking.
  • Unauthorized account access.

Operational Fix

Recommended remediation, mitigation, and detection steps

The technical teams responsible for managing Plane deployments, likely including platform or application owners, should prioritize identifying all instances of the tool. Given the potential for account takeover, it's crucial to determine reachability and business criticality for each deployment to inform remediation planning and risk-based prioritization.

  • Identify accountable application owners.
  • Verify affected OAuth provider configurations.
  • Plan coordinated updates and access reviews.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Plane and how is it used?

Plane is an open-source project management platform. Teams typically host it as a web-based interface to organize tasks and facilitate collaboration. Because it acts as a central hub for project data, it is often deployed on networks where users can access it remotely to track work.

How does CVE-2026-105640 impact account security?

This vulnerability involves improper authentication and spoofing, specifically classified as CWE-287 and CWE-290. It occurs because Plane trusts incoming email data from certain OAuth providers without verifying that the sender actually owns that address. If an attacker controls an identity on a linked provider, they can manipulate their email to match a victim's, tricking Plane into granting them access to the victim's existing account.

Do I need specific OAuth settings to be at risk?

Yes. This bug only triggers if you use Gitea or self-managed GitLab as an OAuth provider with email confirmation disabled. It does not affect instances using verified identity providers like Google, GitHub, or public GitLab.com, as these services confirm email ownership before passing data to Plane.

Why does Halo Surface Signal categorize this as an external threat?

Halo Surface Signal flags this as likely needing attention because project management tools like Plane are commonly configured as web-based, network-accessible applications. Since the application interface is often exposed to the internet or wide-area networks to support remote teams, the potential for unauthorized access via this OAuth flaw is significantly increased.

When should I update my Plane deployment?

You should prioritize updating to version 1.4.0 or later immediately. First, confirm if your instance uses Gitea or self-managed GitLab OAuth. If you use these providers, verify your email confirmation settings and plan an update to the latest version to patch the identity verification logic and secure your user accounts.

References