CVE-2026-105640 - Plane: Account Takeover via Unverified OAuth Email Match (Gitea, self-managed GitLab)
CVE ID :CVE-2026-105640 Published : Oct. 5, 2026, 6:11 p.m. | 1 hour, 16 minutes ago Description :Plane is an open-source project management tool. Prior to 1.4.0, Plane trusts email addresses returned by Gitea OAuth and by self-managed GitLab OAuth deployments where email confirmation is...