Sceawere

Vulnerability Detail

CVE-2026-104961UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Plane Workspace Authorization Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
2h ago
Vendor
makeplane
Product
plane
Attack Type
CWE-863: Incorrect Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Plane is an open-source project management tool. Prior to 1.4.0, WorkspaceOwnerPermission does not require is_active=True when checking whether a user is a workspace owner. A deactivated user can therefore remain authorized as the workspace owner and retain owner-level access. This issue is fixed in 1.4.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-10-05T17:17:11.460Z",
  "pubdate": "2026-10-05T17:17:11.460Z",
  "executiveSummary": "A broken access control vulnerability exists in Plane versions prior to 1.4.0, specifically within the WorkspaceOwnerPermission mechanism.\nThe vulnerability stems from a failure to validate the user account status (is_active=True) during the authorization process for workspace ownership.\nThis flaw allows users whose accounts have been formally deactivated or suspended to maintain active, authorized access to workspace owner-level operations.\nThe risk implication is significant as it undermines the account lifecycle management process, potentially allowing unauthorized access by terminated employees or compromised accounts that have been flagged as inactive.\nAn attacker must have possessed valid credentials for a workspace owner account prior to its deactivation to exploit this vulnerability.\nThis represents a failure in security policy enforcement where account state is not properly synchronized with authorization logic, resulting in persistent privilege retention despite administrative intervention.",
  "technicalDetails": "The vulnerability resides in the application's permission enforcement logic, specifically within the WorkspaceOwnerPermission class responsible for validating whether a user possesses administrative ownership rights over a workspace.\nIn the affected versions of Plane, the authorization check logic evaluates the identity of the user but fails to verify the status attribute of the user model, specifically the is_active flag, during the permission assessment phase.\nStandard Django or similar framework-based access control implementations typically require a check for the is_active property to ensure that only enabled users can interact with restricted endpoints.\nThe attack flow proceeds as follows: An administrator deactivates a workspace owner account within the Plane platform, intending to revoke all access privileges. However, because the WorkspaceOwnerPermission middleware or decorator performs its authorization check by querying the database for the user's role without verifying if the account state is set to active, the session or token associated with the deactivated user remains valid for owner-level requests.\nWhen the deactivated user submits an API request or interacts with the dashboard, the application verifies that the user is the workspace owner based on existing database records. The check returns a positive authorization result, as the system does not perform the supplemental verification of the is_active flag. Consequently, the application grants the user access to sensitive administrative functions, such as modifying workspace configurations, managing other members, or deleting resources.\nThis bypass effectively renders the account deactivation feature useless for revoking access to workspace owners. The vulnerability is restricted to users who were previously designated as owners and have not had their specific workspace role association removed, only their global account status modified to inactive.\nThe root cause is a deficiency in the authorization middleware where the logical predicate for access control is incomplete. By failing to include a filter or conditional check for is_active=True, the application trusts the stored role association implicitly, ignoring the account lifecycle state managed by the system administrator.\nPost-exploitation impact includes unauthorized administrative actions, potential data exfiltration, or destructive configuration changes performed by a user who should have been restricted by the platform's security controls."
}
CVE-2026-104961: Plane Workspace Authorization Bypass (MEDIUM Severity, CVSS: 5.4) | Sceawere