CVE-2026-104961: Plane: WorkspaceOwnerPermission missing is_active check allows deactivated users to retain owner access
Plane is an open-source project management tool. Prior to 1.4.0, WorkspaceOwnerPermission does not require isactive=True when checking whether a user is a workspace owner. A deactivated user can therefore remain authorized as the workspace owner and retain owner-level access. This issue is fixed in 1.4.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
planeto a version that resolves this vulnerability.Fixed in 1.4.0
Event History
Frequently Asked Questions
Which deployments are affected?
Plane versions prior to 1.4.0 are affected. The issue concerns workspace-owner authorization for users who have been deactivated.
What must an attacker have to exploit this issue?
The attacker must be a deactivated Plane user who still has workspace-owner status. No user interaction is required.
What access can a deactivated user retain?
A deactivated user can continue to be authorized as a workspace owner and retain owner-level access to the workspace.
How can the issue be remediated?
Upgrade Plane to version 1.4.0, which adds the required active-user check to WorkspaceOwnerPermission.