External risk intelligence

Plane Default Secrets Enable Account Compromise and Authentication Bypass.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-105641

Plane is a web-based project management tool typically deployed as a web application. Such applications are commonly configured to be internet-facing to allow remote collaboration and access by team members, making their web interfaces and associated service endpoints reachable from the public internet in standard deployment patterns.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the open-source Plane project management tool could allow unauthorized access to systems and user accounts. This issue arises from default, hardcoded security keys that are not randomized in certain deployment configurations, potentially exposing sensitive operational data and authentication mechanisms. The main concern is confirming relevance and exposure to the specific deployments within our environment.

  • Default secrets in Plane could allow unauthorized access.
  • Important if we use Plane for project management.
  • Verify Plane usage and confirm security settings.

Attack Path

How an attacker could exploit the issue

An attacker can compromise accounts or sessions by leveraging default, publicly known secret keys in certain Plane deployments. These secrets, when not overridden by operators, allow an attacker to forge signed data, bypassing authentication checks and potentially gaining full control over user accounts or live services.

  • Publicly exposed default secrets.
  • Forging signed values or bypassing authentication.
  • Account compromise and unauthorized service access.

Live Threat

Current exploitation, exposure, and threat context

When default secrets are not overridden in Plane community deployments, an attacker could leverage them to compromise accounts, sessions, or bypass authentication for live services. This affects web-based project management tools accessible from the public internet.

  • System secrets and user sessions at risk.
  • Attackers exploit default, known secret keys.
  • Compromised accounts and unauthorized service access.

Operational Fix

Recommended remediation, mitigation, and detection steps

The platform or application owner is likely responsible for addressing this vulnerability in Plane, a project management tool. The initial step should be to identify all instances of Plane, confirm their reachability and business criticality, and then determine the accountable owner for remediation planning and vendor coordination if necessary.

  • Platform/application owners should own this.
  • Verify deployment configurations and reachability.
  • Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Plane and how is it used?

Plane is an open-source project management platform used by teams to organize workflows, track tasks, and collaborate on projects. It is a web-based application designed to be self-hosted, allowing organizations to manage their internal development or business operations locally or on their own infrastructure.

What is the vulnerability in CVE-2026-105641?

This vulnerability is classified as CWE-798, which involves the use of hardcoded credentials. In affected versions of Plane, specific deployment manifests contain publicly known default values for secret keys. Because these keys are predictable, they fail to provide the intended security protections for session management and authentication.

How do these hardcoded secrets get triggered?

The vulnerability is triggered when operators deploy Plane using the community manifest configurations without overriding the default keys. It is important to note that this issue does not stem from a flaw in the application's core logic itself, but rather from these specific deployment scripts leaving static, insecure values active instead of generating unique, random secrets during the setup process.

Is my deployment of Plane at risk?

Halo Surface Signal indicates that Plane is typically deployed as a web application intended for remote collaboration, which often makes its interfaces reachable from the public internet. If your instance is accessible via the internet and uses the default community deployment manifests, it faces a higher potential for unauthorized access to accounts or services compared to strictly internal, isolated deployments.

When should I take action for this vulnerability?

You should prioritize verifying your current Plane deployment configuration immediately. First, confirm whether you are running a version prior to 1.4.0. If you are, check if your production environment uses the default secret keys provided in the community manifests. The primary remediation is to upgrade to version 1.4.0, which addresses these defaults, or ensure all secret keys are properly randomized and secured in your current configuration.

References