CVE-2026-27949
Last modified
CVE-2026-27949 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Plane is an an open-source project management tool. Prior to 1.3.0, a vulnerability was identified in Plane's authentication flow where a user's email address is included as a query parameter in the URL during error handling (e.g., when an invalid magic code is submitted). EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
Plane is an an open-source project management tool. Prior to 1.3.0, a vulnerability was identified in Plane's authentication flow where a user's email address is included as a query parameter in the URL during error handling (e.g., when an invalid magic code is submitted). Transmitting personally identifiable information (PII) via GET request query strings is classified as an insecure design practice. The affected code path is located in the authentication utility module (packages/utils/src/auth.ts). This vulnerability is fixed in 1.3.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Plane | Plane | < 1.3.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-27949?
How severe is CVE-2026-27949?
How do I fix CVE-2026-27949?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-27943OpenEMR is a free and open source electronic health records …6.5
- CVE-2026-27944Nginx UI is a web user interface for the Nginx web server. P…9.8
- CVE-2026-27945ZITADEL is an open source identity management platform. Zita…6.5
- CVE-2026-27946ZITADEL is an open source identity management platform. Prio…6.5
- CVE-2026-27947Group-Office is an enterprise customer relationship manageme…8.8
- CVE-2026-27948Copyparty is a portable file server. In versions prior to 1.…6.1
- CVE-2026-2795Use-after-free in the JavaScript: GC component. This vulnera…9.8
- CVE-2026-27950FreeRDP is a free implementation of the Remote Desktop Proto…7.5
- CVE-2026-27951FreeRDP is a free implementation of the Remote Desktop Proto…7.5
- CVE-2026-27952Agenta is an open-source LLMOps platform. In Agenta-API prio…9.9
- CVE-2026-27953ormar is a async mini ORM for Python. Versions 0.23.0 and be…9.8
- CVE-2026-27954Live Helper Chat is an open-source application that enables …6.5
Are you affected by CVE-2026-27949?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
