Sceawere
Vulnerability Detail
CVE-2026-104978UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Plane Improper Authorization Invitation Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.2
- Creation Date
- 3h ago
- Vendor
- makeplane
- Product
- plane
- Attack Type
- CWE-863: Incorrect Authorization
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Plane is an open-source project management tool. Prior to 1.4.0, Plane's project invitation list endpoint is accessible to any authenticated user who knows the workspace slug and project ID, while the public project invitation join endpoint accepts an invitation based only on a submitted email address. When a pending invitation targets an email address that has not registered with Plane, an attacker can enumerate the invitation, register an account using the invited email without mailbox verification, and accept the invitation. The attacker-controlled account is then added to the target workspace and project. This issue is fixed in 1.4.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.2",
"pubDate": "2026-10-05T18:17:33.247Z",
"pubdate": "2026-10-05T18:17:33.247Z",
"executiveSummary": "Plane, an open-source project management tool, contains a critical authorization flaw prior to version 1.4.0 that allows unauthorized access to private workspaces and projects.\nThe vulnerability stems from inadequate validation controls on the project invitation endpoints, specifically regarding the handling of email-based invitations for unregistered users.\nAn attacker can enumerate pending invitations by leveraging known workspace slugs and project IDs. By registering an account with the targeted email address, which lacks mandatory mailbox verification, an attacker can bypass authorization gates to join the project.\nThis vulnerability grants unauthorized individuals full access to internal workspace data and project resources. It represents a significant risk to organizational data confidentiality and integrity.\nExploitation requires only an authenticated Plane account and knowledge of the target workspace identifier, enabling lateral movement and unauthorized project participation.\nThe flaw has been addressed in version 1.4.0, which should be treated as the mandatory security baseline for all deployments.",
"technicalDetails": "The vulnerability exists due to a logic flaw in the invitation management subsystem of Plane, specifically involving the project invitation list endpoint and the public invitation join mechanism.\nThe root cause is twofold: first, the project invitation list endpoint lacks granular access control, allowing any authenticated user to query sensitive invitation metadata if they possess the workspace slug and project ID. Second, the invitation redemption logic fails to enforce cryptographic or verified ownership of the targeted email address during the account registration process.\nThe attack flow proceeds as follows: An attacker identifies a target workspace and project identifier. Using the exposed invitation list endpoint, the attacker enumerates pending invitations to identify email addresses that have not yet registered an account with the platform. Once a target email is identified, the attacker initiates the account registration process for that specific address.\nBecause the platform does not enforce mandatory mailbox verification to confirm ownership of the email address prior to linking it with the invitation, the registration is successful. Subsequently, the attacker calls the public project invitation join endpoint. Since the backend associates the pending invitation solely with the email address, it validates the request and automatically maps the attacker’s newly created, unauthorized account to the internal workspace and project.\nThis bypasses all organizational access controls, granting the attacker the same privileges as an invited member. This includes, but is not limited to, reading internal project tasks, accessing private documentation, and potentially performing modifications depending on the role assigned to the invitation.\nThe vulnerable component is the invitation validation service. The issue affects all versions of Plane prior to 1.4.0. The vulnerability is exploitable by any authenticated user on the platform who can interact with the public-facing API endpoints, necessitating only network access and basic knowledge of the project structure.\nPost-exploitation, the attacker maintains persistent access to the workspace until manually removed by an administrator, providing a platform for data exfiltration, reconnaissance, or further unauthorized actions within the project management environment."
}