CVE-2026-104970
Deferred Deferred - Pending Action

Unauthenticated Instance Admin Creation in Plane

Vulnerability report for CVE-2026-104970, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Plane is an open-source project management tool. From 0.13 until 1.4.0, InstanceAdminSignUpEndpoint in apps/api/plane/license/api/views/admin.py:89-117, 173-229 uses InstanceAdmin.objects.first() for the first-admin check and performs account creation without an atomic transaction, row lock, uniqueness guard, or advisory lock. Two concurrent unauthenticated requests with different email addresses can both observe that no instance administrator exists, create separate User and InstanceAdmin rows, and receive sessions with instance-admin authority. This allows an attacker to share unrestricted instance administration with the legitimate operator. This issue is fixed in 1.4.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
makeplane plane < 1.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-362 The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Time-of-Check to Time-of-Use (TOCTOU) race condition in Plane's InstanceAdminSignUpEndpoint. Two concurrent unauthenticated requests can both pass the initial check for an existing admin before either creates an InstanceAdmin row. This results in two separate admin accounts being created, granting both attackers full instance administration privileges.

Detection Guidance

This vulnerability is specific to the Plane software's InstanceAdminSignUpEndpoint and requires checking for duplicate instance admin accounts. Review Plane logs for concurrent admin creation attempts or multiple admin accounts created in quick succession. No direct network commands detect this, but inspect Plane's database for multiple InstanceAdmin entries with the same Instance ID.

Impact Analysis

An attacker could gain full control over your Plane instance, including workspace administration, license management, and OAuth/SAML configuration. This could lead to complete compromise of your project management system, data theft, or disruption of services.

Compliance Impact

This vulnerability could lead to unauthorized access and control of sensitive data, violating compliance requirements for data protection and access control in standards like GDPR and HIPAA. Unauthorized admin access may result in data breaches, unauthorized modifications, and failure to maintain proper audit trails.

Mitigation Strategies

Upgrade Plane to version 1.4.0 or later to apply the official fix. If upgrading is not immediately possible, implement a database-level UNIQUE constraint on the InstanceAdmin model and add rate-limiting to the InstanceAdminSignUpEndpoint as a temporary measure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104970. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart