The vulnerability exists due to a structural flaw in deployment gate logic for protected environments. High-privileged users can entirely bypass mandated multi-party deployment approval configurations by simply deleting the sole individual user or user group assigned as the approver rule.