CVE-2026-104970: Plane: InstanceAdminSignUpEndpoint TOCTOU race allows two concurrent unauthenticated callers to both bootstrap as Plane instance admins
Plane is an open-source project management tool. From 0.13 until 1.4.0, InstanceAdminSignUpEndpoint in apps/api/plane/license/api/views/admin.py:89-117, 173-229 uses InstanceAdmin.objects.first() for the first-admin check and performs account creation without an atomic transaction, row lock, uniqueness guard, or advisory lock. Two concurrent unauthenticated requests with different email addresses can both observe that no instance administrator exists, create separate User and InstanceAdmin rows, and receive sessions with instance-admin authority. This allows an attacker to share unrestricted instance administration with the legitimate operator. This issue is fixed in 1.4.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Planeto a version that resolves this vulnerability.Fixed in 1.4.0
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Plane versions from 0.13 through versions before 1.4.0 are affected. Exploitation is relevant while no instance administrator exists, because the vulnerable endpoint uses the absence of a first InstanceAdmin as its bootstrap condition.
What does an attacker need to exploit it?
An attacker needs network access to submit unauthenticated signup requests and must race two concurrent requests using different email addresses during initial instance-admin bootstrap. No existing account, privileges, or user interaction are required.
What is the impact if the race succeeds?
Both callers can create separate User and InstanceAdmin records and receive sessions with instance-admin authority. This gives the attacker unrestricted instance administration alongside the legitimate operator.
How can this be remediated?
Upgrade Plane to version 1.4.0, which fixes the issue.