Summary
CVE-2026-105638 is a critical authentication vulnerability in Plane, the open-source project management platform, affecting versions prior to 1.4.0. The magic-code (email OTP) sign-in and sign-up verification endpoints lacked any per-code failed-attempt tracking and bypassed Django REST Framework’s built-in rate throttling, allowing an unauthenticated attacker who knows a victim’s email address to brute-force the six-digit login code within its validity window and take over the account. The flaw carries a CVSS v3.1 base score of 9.1 (Critical).
Technical details
- Root cause: The magic-code verifier endpoint had no counter to track failed code-guess attempts — an incorrect submission did not increment a failure count, invalidate the associated Redis entry, or lock the target email address.
- Throttling bypass: The vulnerable views extended Django’s base
Viewclass instead of DRF’sAPIView, which meant DRF’sAuthenticationThrottle/rate-limiting logic never executed for these endpoints; no equivalent middleware-level rate limiting existed as a backstop. - Trigger conditions: An attacker only needs a target’s email address. The six-digit numeric code space (~900,000 possible values) combined with a multi-minute token TTL and no attempt cap made exhaustive guessing within the code’s lifetime feasible.
- Attack vector: Network, no authentication or user interaction required (AV:N/AC:L/PR:N/UI:N).
- Impact: Successful exploitation allows full account takeover via the magic-link login flow, bypassing password and any configured authentication protections tied to that flow, resulting in high confidentiality and integrity impact.
Affected software
- Plane (makeplane/plane) — all versions prior to 1.4.0
Severity
- CVSS v3.1 Base Score: 9.1 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Mitigation and recommended actions
- Immediate: Upgrade self-hosted Plane instances to version 1.4.0 or later, which introduces a per-token attempt cap (maximum of 5 incorrect code submissions before the token is invalidated), atomic Redis-backed counting to prevent race-condition bypass, and rate limiting applied to the magic-code verification and redirect-flow authentication endpoints.
- If immediate patching is not possible: Disable magic-link/email-OTP login as an authentication method where feasible, and restrict network exposure of the authentication endpoints (e.g., via WAF rate-limiting rules on the magic-code verify path) until the upgrade can be applied.
- Review authentication logs for abnormal volumes of magic-code verification requests against the same account, which may indicate attempted exploitation.

