Summary
CVE-2026-104970 is a time-of-check-to-time-of-use (TOCTOU) race condition in Plane, the open-source project management tool, that allows an unauthenticated attacker to become an instance administrator alongside the legitimate operator during the initial admin bootstrap process. The flaw resides in the InstanceAdminSignUpEndpoint, which checks for an existing admin and creates new admin accounts without any locking or uniqueness enforcement. It affects Plane versions 0.13 through 1.3.1 and carries a CVSS v3.1 base score of 8.1 (High).
Technical details
- Root cause:
InstanceAdminSignUpEndpoint(apps/api/plane/license/api/views/admin.py) usesInstanceAdmin.objects.first()to check whether an instance admin already exists, then creates a newUserandInstanceAdminrecord — without an atomic transaction, row lock (select_for_update()), advisory lock, or database-level uniqueness constraint on the admin record. - Trigger conditions: Under PostgreSQL’s default
READ COMMITTEDisolation level, two unauthenticated requests sent concurrently to the signup endpoint — using different email addresses — can each observe that no instance admin exists before either request commits its insert. - Attack vector: Network-reachable, unauthenticated HTTP requests to the signup endpoint; no user interaction required. CVSS rates attack complexity as High because the attacker must win a narrow race window, typically by firing simultaneous requests.
- Impact: Both requests succeed, resulting in two independent instance-admin accounts. The attacker obtains full instance-administrator authority — including workspace administration, license management, OAuth/SAML configuration, and user lifecycle control — effectively sharing unrestricted control of the Plane instance with the legitimate operator.
Affected software
- makeplane/Plane versions 0.13 through 1.3.1 (all versions prior to 1.4.0)
- Fixed in version 1.4.0
Severity
CVSS v3.1 Base Score: 8.1 (High)
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade Plane to version 1.4.0 or later, which adds proper synchronization (atomic transactions, row-level locking, and uniqueness enforcement) around instance-admin bootstrap.
- If immediate patching is not possible:
- Restrict network access to the instance-admin signup endpoint (e.g., via firewall or reverse-proxy rules) so it is reachable only from trusted management networks during initial setup.
- Complete the initial admin bootstrap immediately after deployment and before exposing the instance to any untrusted network, minimizing the race window.
- Audit existing deployments for unexpected or unrecognized instance-admin accounts and remove any that were not created by the legitimate operator.

