Impact
The flaw lies in the missing requirement for an active status when evaluating workspace ownership, creating an authorization bypass that conforms to CWE‑863. A user who has been deactivated can therefore still be considered a workspace owner and preserve full control over the workspace, enabling actions such as adding or removing collaborators, altering project settings, or deleting data. The impact is limited to instances of owner-level privileges; it does not grant network or system-level access beyond the of the workspace.
Affected Systems
It affects the Makeplane "Plane" project management application in all versions prior to 1.4.0. Any deployment that has not been upgraded to this release is vulnerable. The vulnerability is tied to the WorkspaceOwnerPermission logic within the codebase, as referenced by the security advisory and release notes.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. An exploit would require the ability to identify or target a deactivated user who still holds an owner role, or the power to deactivate an owner themselves. Because the EPSS score is not available, the likelihood of public exploitation is uncertain, and the vulnerability is not listed in the CISA KEV catalog. The risk is mainly for organizations that rely on the proper deactivation of users to enforce role revocation, and the flaw could lead to privilege escalation within the workspace if left unpatched.
OpenCVE Enrichment