Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Oct 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Plane is an open-source project management tool. Prior to 1.4.0, WorkspaceOwnerPermission does not require is_active=True when checking whether a user is a workspace owner. A deactivated user can therefore remain authorized as the workspace owner and retain owner-level access. This issue is fixed in 1.4.0. | |
| Title | Plane: WorkspaceOwnerPermission missing is_active check allows deactivated users to retain owner access | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-05T16:49:26.834Z
Reserved: 2026-10-02T18:16:13.629Z
Link: CVE-2026-104961
No data.
Status : Deferred
Published: 2026-10-05T17:17:11.460
Modified: 2026-10-05T17:17:11.577
Link: CVE-2026-104961
No data.
OpenCVE Enrichment
No data.