Summary
CVE-2026-105641 is a critical use of hard-coded credentials (CWE-798) vulnerability affecting Plane, an open-source project management platform maintained by makeplane. Community (self-hosted) deployment manifests for versions prior to 1.4.0 shipped with fixed, publicly known default values for the Django SECRET_KEY and the LIVE_SERVER_SECRET_KEY, which remained active unless an operator manually overrode them. Because these keys underpin session signing and live-collaboration authentication, their disclosure allows a remote, unauthenticated attacker to forge valid sessions and bypass authentication entirely. The issue has a CVSS v3.1 base score of 9.8 (Critical).
Technical details
- Root cause: The AIO (all-in-one) and CLI deployment templates for Plane hardcoded known, static values for
SECRET_KEY(Django’s cryptographic signing key, used for sessions, password-reset tokens, and email confirmations) andLIVE_SERVER_SECRET_KEY(used to authorize the real-time collaboration/live-server component). These values were not randomized on install and remained active unless an operator explicitly replaced them. - Trigger conditions: Any Plane community/self-hosted instance deployed via the affected AIO or CLI manifests without manually rotating the default secrets.
- Attack vector: Network, no authentication or user interaction required (AV:N/AC:L/PR:N/UI:N). An attacker who knows the publicly disclosed default
SECRET_KEYcan use Django’s signing utilities to forge valid session cookies, password-reset tokens, and other signed values for any account, including administrators. Separately, the disclosedLIVE_SERVER_SECRET_KEYcould be used to bypass live-server access checks, reportedly validated via a plain (non-constant-time) string comparison. - Impact: Full compromise of confidentiality, integrity, and availability — described by the vendor as enabling unauthenticated remote takeover with complete read/write access to all workspace data, including the ability to impersonate any user such as workspace administrators.
Affected software
- Plane (makeplane/plane) community/self-hosted deployments, versions up to and including 1.3.1
- Specifically impacts the AIO (all-in-one) and CLI deployment manifests that embed the default
SECRET_KEYandLIVE_SERVER_SECRET_KEYvalues - Fixed in version 1.4.0
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade self-hosted/community Plane deployments to version 1.4.0 or later, which removes the hardcoded defaults, generates a cryptographically random
SECRET_KEY/LIVE_SERVER_SECRET_KEYon first boot, persists them across restarts, and adds startup checks that warn if a known-insecure or placeholder value is still in use. - If immediate patching is not possible:
- Manually rotate
SECRET_KEYandLIVE_SERVER_SECRET_KEYto unique, randomly generated values in your deployment configuration (do not rely on shipped defaults). - After rotating keys, invalidate existing sessions and force re-authentication for all users, since previously issued signed tokens may have been forged or are no longer valid.
- Audit instances for signs of unauthorized access or session forgery prior to key rotation.
- Restrict network exposure of the live-server/collaboration component where possible until keys are rotated and the instance is patched.
- Manually rotate

