CVE-2026-104974High· 8.1▾ TwilightPlane is an open-source project management tool. Prior to 1.4.0, a user whose account has been deactivated by setting is_active=False can still log in with existing credentials. Successful authentication silently changes is_active back t…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Plane is an open-source project management tool. Prior to 1.4.0, a user whose account has been deactivated by setting is_active=False can still log in with existing credentials. Successful authentication silently changes is_active back to True, reactivating the account without notifying the administrator. This issue is fixed in 1.4.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-104961Medium· 5.4Plane is an open-source project management tool
CVE-2026-105635High· 7.4Plane: Unauthenticated Project Invitation Email Disclosure Enables Unauthorized Project Join Without Token
CVE-2026-105632High· 8.7Plane is an open-source project management tool
CVE-2026-105636Critical· 9.9Plane: SSRF via HTTP redirect in webhook delivery (allow_redirects not set)
CVE-2026-105637Critical· 9.6Plane: Cross-Project Asset Hijacking via 'ProjectBulkAssetEndpoint' (sibling of CVE-2026-46558)
CVE-2026-105638Critical· 9.1Plane: Magic-code verifier endpoint has no rate limit, enabling 6-digit OTP brute force