PatchSiren cyber security CVE debrief
CVE-2026-104978 makeplane CVE debrief
CVE-2026-104978 debrief: Plane project invitation hijack via missing authorization and email-only acceptance. The vulnerability allows an attacker to hijack project invitations by exploiting missing authorization and email-only acceptance in Plane's project invitation list endpoint. This issue is fixed in version 1.4.0. Defenders should assess exposure and prioritize upgrading to version 1.4.0 or later. The vulnerability has a high severity with a CVSS score of 8.2. Affected deployments should be identified and owners assigned for follow-up.
- Vendor
- makeplane
- Product
- plane
- CVSS
- HIGH 8.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-05
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-05
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for managing Plane project instances, particularly those using versions less than 1.4.0, should assess exposure and prioritize upgrading to version 1.4.0 or later.
Why it matters
CVE-2026-104978 is a high-severity vulnerability in the Plane project management tool that allows an attacker to hijack project invitations by exploiting missing authorization and email-only acceptance. Defenders should prioritize verifying exposure and upgrading to version 1.4.0 or later.
- Potential unauthorized account creation
- Possible project membership hijacking
- Required verification of Plane instance exposure
- Necessity to upgrade to version 1.4.0 or later
Technical summary
The Plane project management tool has a vulnerability in its project invitation list endpoint, allowing an attacker to enumerate invitations, register an account using the invited email without mailbox verification, and accept the invitation. The vulnerability has a high severity with a CVSS score of 8.2. Affected deployments should be identified and owners assigned for follow-up. The vulnerability is fixed in version 1.4.0. Defenders should assess exposure and prioritize upgrading to version 1.4.0 or later. The vulnerability allows an attacker to hijack project invitations by exploiting missing authorization and email-only acceptance.
Defensive priority
Defenders should prioritize verifying exposure and upgrading to version 1.4.0 or later.
Recommended defensive actions
- Verify if the Plane project management tool is used in the organization
- Check if the version is less than 1.4.0 and upgrade to 1.4.0 or later if necessary
- Monitor project invitations and join requests for suspicious activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source item provide details on the vulnerability, including its description, affected versions, and fixed version. The Plane project management tool has a vulnerability in its project invitation list endpoint, allowing an attacker to enumerate invitations, register an account using the invited email without mailbox verification, and accept the invitation. The vulnerability has a high severity with a CVSS score of 8.2. Defenders should verify exposure and prioritize upgrading to version 1.4.0 or later. Evidence is 1.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-104978 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-104978
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-104978 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104978
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Plane: Invitation Hijack in Project Join Flow via Missing Authorization and Email-Only Acceptanc
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/104xxx/CVE-2026-104978.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/makeplane/plane/security/advisories/GHSA-g36h-p63v-g9c7
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/makeplane/plane/pull/9308
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/makeplane/plane/commit/14a4c22f94eac1582439e41112213f976c6a6cf7
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/makeplane/plane/releases/tag/v1.4.0
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.