
Business Logic Errors (CWE-840)CVSS 4€0
Business Logic Bypass Allows Setting “Read Access” Role Without Pro Plan Subscription
ziadmomen
Disclosed on HackerOne · March 16, 2026
Publicly disclosed report · by ziadmomen
View original on HackerOneSummary:
A business logic flaw allows a user with a free plan to generate an invitation link that assigns the Read Access (Read) role, even though this role is intended to be restricted to users with a Pro Plan subscription. By manipulating the invitation creation process, an attacker can create an invite link that grants this restricted role without having the required paid subscription.
Steps To Reproduce:
-
Create two accounts one for the owner and the second one for the user who will be invited to the project.
-
From the owner account create a project.
