Sceawere

Vulnerability Detail

CVE-2026-104974UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Plane Improper Authentication Account Reactivation

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
3h ago
Vendor
makeplane
Product
plane
Attack Type
CWE-284: Improper Access Control
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Plane is an open-source project management tool. Prior to 1.4.0, a user whose account has been deactivated by setting is_active=False can still log in with existing credentials. Successful authentication silently changes is_active back to True, reactivating the account without notifying the administrator. This issue is fixed in 1.4.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-10-05T18:17:32.473Z",
  "pubdate": "2026-10-05T18:17:32.473Z",
  "executiveSummary": "Plane, an open-source project management tool, contains an authentication logic vulnerability affecting versions prior to 1.4.0.\nThe flaw stems from an insecure authentication workflow where accounts with the is_active flag set to False are implicitly and automatically reactivated upon successful login with valid credentials.\nThis vulnerability effectively bypasses administrative account deactivation controls, allowing previously disabled users to regain full system access without administrator intervention or notification.\nThe risk is critical in environments where account deactivation is used as a security measure to revoke access for terminated personnel or compromised accounts.\nAn attacker possessing valid but deactivated credentials can exploit this by simply authenticating to the platform, triggering an automatic state change in the user profile.\nNo complex exploitation techniques are required; the issue resides in the core authentication routine's failure to enforce a hard block on deactivated user accounts during the session establishment process.",
  "technicalDetails": "The vulnerability exists within the Plane authentication mechanism, specifically within the logic responsible for session validation and user account state verification.\nIn affected versions (pre-1.4.0), the application fails to enforce an unconditional rejection for user accounts where the is_active property is set to False within the database.\nThe root cause is an insecure implementation of the login handler, which fails to check the account's activation status before proceeding with session token generation.\nWhen a user with an is_active=False status submits valid authentication credentials (e.g., username and password), the backend performs the authentication check successfully.\nUpon a successful credential match, the application proceeds to finalize the authentication process by updating the user's account state, effectively setting is_active to True.\nThis side effect silently reactivates the account without any logging, alerting, or administrative authorization required, violating the principle of least privilege and undermining organizational access control policies.\nThe attack flow is straightforward: 1) An administrator deactivates a target account; 2) The target user authenticates using their existing (but disabled) credentials; 3) The backend processes the valid credentials; 4) The authentication logic updates the user record, toggling is_active to True; 5) The user is granted an active session and access to the project management interface.\nThis behavior persists across all deployment configurations where the vulnerable authentication module is active. The vulnerability is exploitable remotely over the network, provided the attacker has valid credentials that were previously disabled. The impact includes unauthorized access to sensitive project data, potential data manipulation, and the persistent subversion of account management workflows.\nPost-exploitation, the user account remains in an active state, potentially allowing for long-term unauthorized access until an administrator manually identifies and deactivates the account again, though the cycle can be repeated indefinitely by the attacker."
}
CVE-2026-104974: Plane Improper Authentication Account Reactivation (HIGH Severity, CVSS: 8.1) | Sceawere