PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-104978 makeplane CVE debrief

CVE-2026-104978 debrief: Plane project invitation hijack via missing authorization and email-only acceptance. The vulnerability allows an attacker to hijack project invitations by exploiting missing authorization and email-only acceptance in Plane's project invitation list endpoint. This issue is fixed in version 1.4.0. Defenders should assess exposure and prioritize upgrading to version 1.4.0 or later. The vulnerability has a high severity with a CVSS score of 8.2. Affected deployments should be identified and owners assigned for follow-up.

Vendor
makeplane
Product
plane
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-05
Original CVE updated
2026-10-07
Advisory published
2026-10-05
Advisory updated
2026-10-07

Who should care

Defenders responsible for managing Plane project instances, particularly those using versions less than 1.4.0, should assess exposure and prioritize upgrading to version 1.4.0 or later.

Why it matters

CVE-2026-104978 is a high-severity vulnerability in the Plane project management tool that allows an attacker to hijack project invitations by exploiting missing authorization and email-only acceptance. Defenders should prioritize verifying exposure and upgrading to version 1.4.0 or later.

  • Potential unauthorized account creation
  • Possible project membership hijacking
  • Required verification of Plane instance exposure
  • Necessity to upgrade to version 1.4.0 or later

Technical summary

The Plane project management tool has a vulnerability in its project invitation list endpoint, allowing an attacker to enumerate invitations, register an account using the invited email without mailbox verification, and accept the invitation. The vulnerability has a high severity with a CVSS score of 8.2. Affected deployments should be identified and owners assigned for follow-up. The vulnerability is fixed in version 1.4.0. Defenders should assess exposure and prioritize upgrading to version 1.4.0 or later. The vulnerability allows an attacker to hijack project invitations by exploiting missing authorization and email-only acceptance.

Defensive priority

Defenders should prioritize verifying exposure and upgrading to version 1.4.0 or later.

Recommended defensive actions

  • Verify if the Plane project management tool is used in the organization
  • Check if the version is less than 1.4.0 and upgrade to 1.4.0 or later if necessary
  • Monitor project invitations and join requests for suspicious activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and source item provide details on the vulnerability, including its description, affected versions, and fixed version. The Plane project management tool has a vulnerability in its project invitation list endpoint, allowing an attacker to enumerate invitations, register an account using the invited email without mailbox verification, and accept the invitation. The vulnerability has a high severity with a CVSS score of 8.2. Defenders should verify exposure and prioritize upgrading to version 1.4.0 or later. Evidence is 1.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-104978 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-104978

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-104978 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104978

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Plane: Invitation Hijack in Project Join Flow via Missing Authorization and Email-Only Acceptanc

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/104xxx/CVE-2026-104978.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/makeplane/plane/security/advisories/GHSA-g36h-p63v-g9c7

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/makeplane/plane/pull/9308

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/makeplane/plane/commit/14a4c22f94eac1582439e41112213f976c6a6cf7

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/makeplane/plane/releases/tag/v1.4.0

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.