Open Source Project Management Tool Vulnerability in Plane Affects Account Management
CVE-2026-104970

8.1HIGH

Key Information:

Vendor

Makeplane

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-104970?

The Plane open-source project management tool has a vulnerability that allows two concurrent unauthenticated requests to exploit a lack of transaction atomicity and proper locking mechanisms. Specifically, it fails to enforce any uniqueness guard when creating instance administrator accounts. As a result, attackers can potentially gain unauthorized instance admin privileges, enabling them to share unrestricted control over the instance with legitimate operators. This issue was rectified in version 1.4.0, which implemented necessary fixes to secure the account creation process.

Affected Version(s)

plane < 1.4.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.