Skip to main content
Vulnerability Database/CVE-2026-105641

CVE-2026-105641: Plane Project Management Auth Bypass Flaw

CVE-2026-105641 is an authentication bypass flaw in Plane project management tool caused by hardcoded SECRET_KEY values that allow attackers to forge Django sessions and compromise accounts. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2026-105641 Overview

Plane, an open-source project management tool, ships community deployment manifests containing hardcoded SECRET_KEY and LIVE_SERVER_SECRET_KEY values. The deployments/aio/community/ and deployments/cli/community/ manifests use publicly known defaults that remain active unless operators manually override them. The top-level setup.sh script randomizes secrets only for the development Docker Compose path, leaving community deployments exposed. The issue is fixed in version 1.4.0.

Critical Impact

Knowledge of SECRET_KEY lets attackers forge Django-signed values to compromise accounts and sessions. Knowledge of LIVE_SERVER_SECRET_KEY bypasses live-service authentication on unchanged community deployments.

Affected Products

  • Plane (makeplane/plane) all versions prior to 1.4.0
  • deployments/aio/community/ manifest deployments
  • deployments/cli/community/ manifest deployments

Discovery Timeline

  • 2026-10-05 - CVE-2026-105641 published to NVD
  • 2026-10-07 - Last updated in NVD database

Technical Details for CVE-2026-105641

Vulnerability Analysis

The vulnerability falls under [CWE-798] Use of Hard-coded Credentials. Plane's community deployment manifests ship with two fixed secrets: SECRET_KEY set to 60gp0byfz2dvffa45cxl20p1scy9xbpf6d8c5y0geejgkyp1b5 and LIVE_SERVER_SECRET_KEY set to htbqvBJAgpm9bzvf3r4urJer0ENReatceh. These values are visible in the public GitHub repository and remain active across every unmodified community installation.

Django uses SECRET_KEY to sign sessions, CSRF tokens, password reset tokens, and other security-sensitive values. An attacker who knows the key can forge any of these signed values. The LIVE_SERVER_SECRET_KEY protects live-service authentication; its disclosure allows direct bypass of that control.

Root Cause

The setup.sh script generates random secrets only for the development Docker Compose path. The aio and cli community deployment manifests were never wired into that randomization logic. Operators who deploy with defaults inherit the shared, publicly known production secrets without any warning.

Attack Vector

The flaw is exploitable over the network with no authentication or user interaction. An attacker enumerates internet-facing Plane community deployments, uses the published SECRET_KEY to forge a Django session cookie or password reset token for an administrative account, and gains full application access. The same attacker can forge requests to live-service endpoints using the known LIVE_SERVER_SECRET_KEY.

python
# Security patch in apps/api/plane/settings/common.py
BASE_DIR = os.path.dirname(os.path.dirname(os.path.abspath(__file__)))

-# Secret Key
-SECRET_KEY = os.environ.get("SECRET_KEY", get_random_secret_key())
+_logger = logging.getLogger("plane")
+
+# Secret Key — use `or` so an explicitly empty env var is treated the same as unset,
+# falling back to a random key rather than passing "" to Django (GHSA-cmwv-pjmw-8483).
+SECRET_KEY = os.environ.get("SECRET_KEY") or get_random_secret_key()
+# Refuse to run silently with a publicly-known or placeholder SECRET_KEY.
+_INSECURE_SECRET_KEYS = {
+    "60gp0byfz2dvffa45cxl20p1scy9xbpf6d8c5y0geejgkyp1b5",  # old publicly-known default
+    "change-this-key-on-deployment",  # placeholder shipped in community templates
+}
+if SECRET_KEY in _INSECURE_SECRET_KEYS:
+    _logger.critical(
+        "SECURITY: SECRET_KEY is set to a known insecure or placeholder value. "
+        "This makes your installation vulnerable to session forgery, CSRF bypass, and "
+        "password-reset token forging. Set a unique SECRET_KEY before deploying to production."
+    )

Source: GitHub Commit 1acc69e

Detection Methods for CVE-2026-105641

Indicators of Compromise

  • Presence of SECRET_KEY=60gp0byfz2dvffa45cxl20p1scy9xbpf6d8c5y0geejgkyp1b5 in running Plane container environment variables.
  • Presence of LIVE_SERVER_SECRET_KEY=htbqvBJAgpm9bzvf3r4urJer0ENReatceh in deployed configuration.
  • Unexpected administrative sessions or password-reset events in Plane audit logs with no corresponding user action.

Detection Strategies

  • Inspect container environment and Compose files for the two publicly known default values.
  • Compare the Plane deployment version against 1.4.0 and verify which community manifest was used.
  • Review authentication logs for session cookies validated against the default SECRET_KEY and any live-service calls using the default LIVE_SERVER_SECRET_KEY.

Monitoring Recommendations

  • Alert on new admin logins and privilege changes in Plane that lack a prior interactive login event.
  • Monitor outbound traffic from Plane hosts for unexpected API calls to internal live-service endpoints.
  • Track configuration drift on deployment manifests to catch reintroduction of hardcoded secrets.

How to Mitigate CVE-2026-105641

Immediate Actions Required

  • Upgrade Plane to version 1.4.0 or later, which removes the hardcoded defaults and auto-generates secrets on first boot.
  • Rotate both SECRET_KEY and LIVE_SERVER_SECRET_KEY on every existing community deployment, even after patching.
  • Invalidate all active sessions and force password resets after secret rotation.
  • Review audit logs for signs of forged sessions or unauthorized live-service calls prior to remediation.

Patch Information

The fix is included in Plane v1.4.0. See the GitHub Release v1.4.0, Pull Request #9291, and Security Advisory GHSA-cmwv-pjmw-8483. The patch falls back to get_random_secret_key() when SECRET_KEY is unset or empty and emits a critical log entry if a known insecure value is detected.

Workarounds

  • Explicitly set strong, unique values for SECRET_KEY and LIVE_SERVER_SECRET_KEY via environment variables before starting Plane.
  • Restrict network exposure of community deployments to trusted networks until the upgrade is applied.
  • Place Plane behind an authenticating reverse proxy to limit anonymous access to signed endpoints.
bash
# Generate a strong SECRET_KEY and export before deployment
export SECRET_KEY="$(python3 -c 'from django.utils.crypto import get_random_secret_key; print(get_random_secret_key())')"
export LIVE_SERVER_SECRET_KEY="$(openssl rand -base64 48)"

# Verify defaults are not present in the running container
docker exec plane-api printenv SECRET_KEY LIVE_SERVER_SECRET_KEY

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.