CVE-2026-105638

Deferred
Published: 05 Oct 2026, 18:09
Last modified:05 Oct 2026, 18:44

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.1 CRITICAL
v3.1 (cve.org)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

05 Oct 2026, 18:09
Published
Vulnerability first disclosed
05 Oct 2026, 18:44
Last Modified
Vulnerability information updated

Description

Plane is an open-source project management tool. Prior to 1.4.0, Plane's magic-code email login uses a six-digit numeric OTP with approximately 20 bits of entropy. The verifier has no per-code failed-attempt counter, and an incorrect code does not increment a counter, invalidate the Redis entry, or lock the email address. The verifier extends django.views.View rather than DRF's APIView, so the configured AnonRateThrottle limit does not apply. The middleware stack also contains no Django-level rate limiter such as django-ratelimit, django-axes, or an IP-throttling middleware. This vulnerability is fixed in 1.4.0.

CVSS Metrics

  • v3.1•CRITICAL•Score: 9.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Techniques & Countermeasures

  • CWE-307•Improper Restriction of Excessive Authentication Attempts

    The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Affected Systems

  • makeplane•plane

    < 1.4.0

References (4)