Sceawere

Vulnerability Detail

CVE-2026-105640UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Plane Improper OAuth Email Validation

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
3h ago
Vendor
makeplane
Product
plane
Attack Type
CWE-287: Improper Authentication
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Plane is an open-source project management tool. Prior to 1.4.0, Plane trusts email addresses returned by Gitea OAuth and by self-managed GitLab OAuth deployments where email confirmation is disabled, without verifying that the provider authenticated ownership of the address. An attacker can set an OAuth identity's unverified provider email to a victim's address, which Plane matches directly to the victim's existing local account. The attacker can then log in to the victim's Plane account without knowing the victim's password. GitHub, GitLab.com, and Google are not affected because those providers return verified email addresses. This issue is fixed in 1.4.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-10-05T19:17:18.383Z",
  "pubdate": "2026-10-05T19:17:18.383Z",
  "executiveSummary": "Plane, an open-source project management tool, contains a critical vulnerability regarding the improper validation of OAuth identity assertions. The application fails to verify the authenticity of email addresses returned by specific OAuth providers, specifically Gitea and self-managed GitLab instances where email confirmation is disabled.\nThis flaw allows an attacker to perform an account takeover by manipulating the OAuth profile to match an existing user's email address within the Plane instance. Because the application trusts unverified identity attributes, it incorrectly authenticates the attacker as the victim.\nThis vulnerability poses a significant risk to organizational security, as it grants unauthorized access to sensitive project data and administrative functions without requiring knowledge of the victim's credentials. The exploitation is primarily limited to environments configured with specific OAuth providers that do not enforce email verification by default. The issue is resolved in version 1.4.0.",
  "technicalDetails": "The vulnerability resides in the authentication middleware responsible for processing OAuth callbacks in Plane prior to version 1.4.0. The application logic incorrectly assumes that all email addresses provided via the OAuth identity object are cryptographically verified by the identity provider (IdP).\nRoot Cause Analysis: When integrating with Gitea or self-managed GitLab deployments, Plane performs a direct mapping between the email attribute returned by the IdP and the internal user record stored in its local database. The application does not check the 'email_verified' flag or equivalent assertion metadata provided in the OAuth profile. Consequently, if a self-managed IdP allows the registration of an account with an unverified email address, the IdP will return this attacker-controlled email during the OAuth handshake.\nAttack Flow: 1. The attacker creates an account on a self-managed Gitea or GitLab instance using a victim's email address as their identity. 2. The attacker initiates the OAuth flow in the vulnerable Plane instance. 3. Upon successful redirection, the OAuth provider sends an identity object containing the victim's email address to the Plane application. 4. Plane receives the identity object and, due to lack of verification, performs a lookup in the local user database to match the email. 5. Finding a corresponding account, Plane logs the attacker into the victim's session, bypassing standard password authentication.\nScope and Impact: This vulnerability affects Plane instances relying on Gitea or self-managed GitLab for authentication. Major providers like GitHub, GitLab.com, and Google are unaffected because they provide verified email status which prevents the ingestion of spoofed identity data. Post-exploitation, the attacker gains full access to the victim's account, allowing for the exfiltration of private project data, modification of workflows, or elevation of privileges if the target is an administrator.\nComplexity and Requirements: The attacker requires access to configure or exploit an OIDC/OAuth provider that permits the association of arbitrary, unverified email addresses with an identity profile. No specific network access to the Plane backend is required beyond that which is available to a standard user initiating an OAuth flow."
}
CVE-2026-105640: Plane Improper OAuth Email Validation (CRITICAL Severity, CVSS: 9.1) | Sceawere