Open Source Project Management Tool Vulnerability in Plane Affects Account Management
CVE-2026-104970
8.1HIGH
What is CVE-2026-104970?
The Plane open-source project management tool has a vulnerability that allows two concurrent unauthenticated requests to exploit a lack of transaction atomicity and proper locking mechanisms. Specifically, it fails to enforce any uniqueness guard when creating instance administrator accounts. As a result, attackers can potentially gain unauthorized instance admin privileges, enabling them to share unrestricted control over the instance with legitimate operators. This issue was rectified in version 1.4.0, which implemented necessary fixes to secure the account creation process.
Affected Version(s)
plane < 1.4.0
