Description
Plane is an open-source project management tool. Prior to 1.4.0, WorkspaceOwnerPermission does not require is_active=True when checking whether a user is a workspace owner. A deactivated user can therefore remain authorized as the workspace owner and retain owner-level access. This issue is fixed in 1.4.0.
Published: 2026-10-05
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Owner Access
Action: Patch to v1.4.0
AI Analysis

Impact

The flaw lies in the missing requirement for an active status when evaluating workspace ownership, creating an authorization bypass that conforms to CWE‑863. A user who has been deactivated can therefore still be considered a workspace owner and preserve full control over the workspace, enabling actions such as adding or removing collaborators, altering project settings, or deleting data. The impact is limited to instances of owner-level privileges; it does not grant network or system-level access beyond the of the workspace.

Affected Systems

It affects the Makeplane "Plane" project management application in all versions prior to 1.4.0. Any deployment that has not been upgraded to this release is vulnerable. The vulnerability is tied to the WorkspaceOwnerPermission logic within the codebase, as referenced by the security advisory and release notes.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate severity. An exploit would require the ability to identify or target a deactivated user who still holds an owner role, or the power to deactivate an owner themselves. Because the EPSS score is not available, the likelihood of public exploitation is uncertain, and the vulnerability is not listed in the CISA KEV catalog. The risk is mainly for organizations that rely on the proper deactivation of users to enforce role revocation, and the flaw could lead to privilege escalation within the workspace if left unpatched.

Generated by OpenCVE AI on October 5, 2026 at 18:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Plane to version 1.4.0 or later, where the is_active check is enforced.
  • Revoke owner roles from all users who are currently deactivated after the upgrade to prevent lingering permissions.
  • Audit workspace ownership assignments regularly to ensure deactivated users do not retain owner status.

Generated by OpenCVE AI on October 5, 2026 at 18:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Makeplane
Makeplane plane
Vendors & Products Makeplane
Makeplane plane

Mon, 05 Oct 2026 17:00:00 +0000

Type Values Removed Values Added
Description Plane is an open-source project management tool. Prior to 1.4.0, WorkspaceOwnerPermission does not require is_active=True when checking whether a user is a workspace owner. A deactivated user can therefore remain authorized as the workspace owner and retain owner-level access. This issue is fixed in 1.4.0.
Title Plane: WorkspaceOwnerPermission missing is_active check allows deactivated users to retain owner access
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-05T16:49:26.834Z

Reserved: 2026-10-02T18:16:13.629Z

Link: CVE-2026-104961

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-05T17:17:11.460

Modified: 2026-10-05T17:17:11.577

Link: CVE-2026-104961

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T18:45:19Z

Weaknesses