CVE-2026-104978: Plane: Invitation Hijack in Project Join Flow via Missing Authorization and Email-Only Acceptance

Published Oct 5, 2026
·
Updated

Plane is an open-source project management tool. Prior to 1.4.0, Plane's project invitation list endpoint is accessible to any authenticated user who knows the workspace slug and project ID, while the public project invitation join endpoint accepts an invitation based only on a submitted email address. When a pending invitation targets an email address that has not registered with Plane, an attacker can enumerate the invitation, register an account using the invited email without mailbox verification, and accept the invitation. The attacker-controlled account is then added to the target workspace and project. This issue is fixed in 1.4.0.

Affected Software

1 affected component
Plane Plane<1.4.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Plane to a version that resolves this vulnerability.

    Fixed in 1.4.0

Event History

Oct 5, 2026
CVE Published
via MITRE·05:48 PM
Data Sourced
via MITRE·05:48 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which invitations are vulnerable to takeover?

Pending invitations sent to email addresses that have not yet registered with Plane are vulnerable. An attacker can register an account using the invited address without mailbox verification and then accept the invitation.

2

What does an attacker need to exploit this issue?

The attacker needs an authenticated Plane account, the target workspace slug and project ID, and a pending invitation for an unregistered email address. Exploitation also relies on the invitation list endpoint being accessible to authenticated users and the join endpoint accepting an email address alone.

3

What access does successful exploitation provide?

The attacker-controlled account is added to the target workspace and project. The vulnerability has high confidentiality and integrity impact and affects a different security scope.

4

What version fixes the issue?

Upgrade Plane to version 1.4.0 or later. Versions prior to 1.4.0 are affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203