CVE-2026-104961
Deferred Deferred - Pending Action

Plane WorkspaceOwnerPermission Authorization Bypass in Deactivated Users

Vulnerability report for CVE-2026-104961, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Plane is an open-source project management tool. Prior to 1.4.0, WorkspaceOwnerPermission does not require is_active=True when checking whether a user is a workspace owner. A deactivated user can therefore remain authorized as the workspace owner and retain owner-level access. This issue is fixed in 1.4.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
makeplane plane < 1.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Plane, an open-source project management tool, allows deactivated user accounts to retain owner-level access to workspaces. The issue occurs because the WorkspaceOwnerPermission class does not check if a user is active (is_active=True) when verifying ownership. This flaw enables removed or deactivated users to maintain unauthorized access to workspace resources.

Impact Analysis

If you use Plane versions prior to 1.4.0, deactivated users could retain access to sensitive workspace data, manage invitations, or perform owner-level actions. This could lead to unauthorized access, data breaches, or misuse of workspace resources by former members.

Compliance Impact

This vulnerability may violate data protection regulations like GDPR or HIPAA by allowing unauthorized access to sensitive user data. Non-compliance could result from improper user access controls, failure to revoke access promptly, or inability to ensure data integrity and confidentiality.

Mitigation Strategies

Upgrade Plane to version 1.4.0 or later to address the vulnerability. Review user accounts marked as inactive to ensure they do not retain owner-level access. Check workspace admin permissions to confirm only active users have elevated roles.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104961. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart