Sceawere

Vulnerability Detail

CVE-2026-105641UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Hardcoded Cryptographic Secrets in Plane

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
2h ago
Vendor
makeplane
Product
plane
Attack Type
CWE-798: Use of Hard-coded Credentials
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Plane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and deployments/cli/community/ manifests provide fixed, publicly known SECRET_KEY and LIVE_SERVER_SECRET_KEY defaults that remain active when operators do not override them. The top-level setup.sh randomizes secrets only for the development Docker Compose path, leaving unchanged aio and cli community deployments with shared production secrets. Knowledge of SECRET_KEY enables attackers to forge Django-signed values and compromise accounts or sessions. Knowledge of LIVE_SERVER_SECRET_KEY bypasses live-service authentication on unchanged community deployments. This issue is fixed in 1.4.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-10-05T19:17:18.560Z",
  "pubdate": "2026-10-05T19:17:18.560Z",
  "executiveSummary": "Plane, an open-source project management tool, is susceptible to a critical vulnerability involving hardcoded cryptographic secrets in specific deployment manifests prior to version 1.4.0.\nThe vulnerability type is categorized as Use of Hard-coded Cryptographic Key, which facilitates unauthorized access and potential remote code execution or session hijacking.\nThe affected components include the 'deployments/aio/community/' and 'deployments/cli/community/' manifest paths. These directories contain static, publicly known default values for 'SECRET_KEY' and 'LIVE_SERVER_SECRET_KEY'.\nBecause these defaults persist if not explicitly overridden by the operator, production instances are exposed to significant security risks.\nAn unauthenticated attacker with knowledge of these static keys can forge Django-signed values to compromise user accounts or sessions, and bypass authentication mechanisms for live services.\nThe risk is severe as it enables full application compromise by allowing the manipulation of secure tokens and the bypass of cryptographic integrity checks mandated by the framework.\nExploitation requires no special privileges; an attacker merely needs to identify an instance where the default deployment manifests were used without rotation or configuration override of the environmental secrets.",
  "technicalDetails": "The root cause of this vulnerability lies in the inclusion of predictable, static configuration values within the repository's production deployment manifests. In versions prior to 1.4.0, the 'deployments/aio/community/' and 'deployments/cli/community/' directories contained predefined values for the Django 'SECRET_KEY' and the 'LIVE_SERVER_SECRET_KEY'.\nThe 'SECRET_KEY' in Django is a fundamental cryptographic primitive used for signing session cookies, password reset tokens, and other sensitive serialized data. When this key is known to an attacker, it enables the forging of cryptographically valid, signed payloads. By crafting these payloads, an attacker can perform session hijacking, assume administrative privileges, or manipulate state-changing requests that rely on signed integrity tokens.\nFurthermore, the 'LIVE_SERVER_SECRET_KEY' is utilized to gate authentication for live-service communications. The presence of a static default key allows an attacker to bypass these authentication layers entirely, facilitating unauthorized access to real-time features and data streams.\nThe attack flow proceeds as follows: First, the attacker identifies a Plane instance deployed using the community manifests without custom environment variable overrides. Second, the attacker utilizes the known, repository-default keys to sign malicious inputs or decode/manipulate existing session identifiers. Third, by submitting these crafted values to the application, the attacker bypasses standard authentication controls. Consequently, the attacker achieves post-exploitation capabilities including full session impersonation and unauthorized access to project data.\nWhile the 'setup.sh' script implemented secret randomization for the development Docker Compose path, the production-intended community manifests remained stagnant, creating a false sense of security for operators who did not manually rotate these credentials. The vulnerability resides in the static nature of these manifests relative to the sensitive secrets they are intended to protect. This represents a failure in secure default configuration practices, where sensitive environmental credentials were committed to the source control system in plaintext, making them accessible to any actor with knowledge of the project's source code history."
}
CVE-2026-105641: Hardcoded Cryptographic Secrets in Plane (CRITICAL Severity, CVSS: 9.8) | Sceawere