Skip to main content
Vulnerability Database/CVE-2026-104961

CVE-2026-104961: Plane Auth Bypass Vulnerability

CVE-2026-104961 is an authentication bypass flaw in Plane that allows deactivated users to retain workspace owner privileges. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-104961 Overview

CVE-2026-104961 is an authorization flaw in Plane, an open-source project management tool. Versions prior to 1.4.0 contain a broken access control issue [CWE-863] in the WorkspaceOwnerPermission check. The permission class fails to require is_active=True when verifying workspace owner status. A deactivated user therefore retains owner-level authorization and can continue to perform privileged workspace actions. The maintainers resolved the issue in version 1.4.0.

Critical Impact

Deactivated workspace owners retain full owner-level access to Plane workspaces, allowing continued read and write operations against workspace resources despite account deactivation.

Affected Products

  • Plane (makeplane/plane) versions prior to 1.4.0
  • Self-hosted Plane deployments relying on WorkspaceOwnerPermission for access control
  • Plane workspaces where user deactivation is used as the primary offboarding control

Discovery Timeline

  • 2026-10-05 - CVE-2026-104961 published to NVD
  • 2026-10-06 - Last updated in NVD database

Technical Details for CVE-2026-104961

Vulnerability Analysis

The vulnerability resides in Plane's Django permission layer at apps/api/plane/app/permissions/workspace.py. The WorkspaceOwnerPermission class queries the WorkspaceMember table to confirm whether the requesting user holds the Admin role for a given workspace slug. The query omits the is_active field, so membership rows belonging to deactivated users still satisfy the check. Any API endpoint protected by this permission grants access to a deactivated owner.

The exposure is limited to users who previously held owner privileges and whose accounts were later deactivated. An attacker cannot leverage this flaw without a valid, authenticated session tied to such an account. Impact includes modification of workspace settings, project data, and member assignments under the compromised owner identity.

Root Cause

The root cause is a missing predicate in the authorization query. The permission class treats role membership as sufficient proof of authorization and never consults the account activation state. This conflates two distinct properties: role assignment and account validity. The pattern is characteristic of [CWE-863: Incorrect Authorization].

Attack Vector

Exploitation requires network access to the Plane API and valid session credentials for a deactivated account that previously held workspace owner status. The attacker issues standard API requests against workspace-scoped endpoints. The server evaluates WorkspaceOwnerPermission, finds a matching Admin membership row, and authorizes the request without checking is_active.

python
            return False

        return WorkspaceMember.objects.filter(
-            workspace__slug=view.workspace_slug, member=request.user, role=Admin
+            workspace__slug=view.workspace_slug, member=request.user, role=Admin, is_active=True
        ).exists()

Source: GitHub Commit 6c9dbb5

Detection Methods for CVE-2026-104961

Indicators of Compromise

  • API requests to /api/v1/workspaces/<slug>/ endpoints originating from user accounts whose is_active flag is False in the Plane database.
  • Audit log entries showing workspace configuration changes performed by accounts that administrators have offboarded.
  • Authenticated session tokens tied to deactivated users that remain valid against workspace-owner-protected routes.

Detection Strategies

  • Correlate Plane application logs with the WorkspaceMember table to identify requests from members where is_active=False.
  • Query the Plane database for rows in WorkspaceMember with role=Admin and is_active=False and alert on any API activity attributed to those member_id values.
  • Review reverse proxy or WAF logs for authenticated API calls to workspace-scoped paths following known user deactivation events.

Monitoring Recommendations

  • Forward Plane API and authentication logs to a centralized logging platform and alert on privileged operations performed by deactivated users.
  • Baseline the set of active workspace owners per workspace and alert on deviations following HR offboarding workflows.
  • Monitor the Plane release channel and the GitHub Security Advisory GHSA-wjgv-cq7w-258v for related guidance.

How to Mitigate CVE-2026-104961

Immediate Actions Required

  • Upgrade all Plane instances to version 1.4.0 or later as published in the GitHub Release v1.4.0.
  • Audit the WorkspaceMember table for role=Admin records where is_active=False and remove or reassign those memberships.
  • Invalidate active sessions and revoke API tokens for any user accounts that have been deactivated.

Patch Information

The fix is included in Plane 1.4.0. Commit 6c9dbb5 adds is_active=True to the WorkspaceOwnerPermission query and introduces additional hardening to block deactivated user login. See the GitHub Pull Request Discussion for implementation context.

Workarounds

  • Remove deactivated users from the WorkspaceMember table rather than relying on the is_active flag alone for offboarding.
  • Apply the single-line patch to apps/api/plane/app/permissions/workspace.py as an interim fix if upgrading immediately is not feasible.
  • Restrict network access to the Plane API from untrusted networks to reduce the attack surface until patching is complete.
bash
# Verify installed Plane version and upgrade
docker compose pull
docker compose down
docker compose up -d

# Audit deactivated admins still present as workspace members
# (run inside the Plane database)
# SELECT workspace_id, member_id FROM workspace_members wm
#   JOIN users u ON u.id = wm.member_id
#   WHERE wm.role = 20 AND u.is_active = false;

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.