Plane · Plane · CVE-2026-104970
**Name of the Vulnerable Software and Affected Versions**
Plane versions 0.13 through 1.3.x
**Description**
An issue exists in the `InstanceAdminSignUpEndpoint` within `apps/api/plane/license/api/views/admin.py` where the system uses `InstanceAdmin.objects.first()` to verify if an administrator already exists. Because account creation is performed without an atomic transaction, row lock, uniqueness guard, or advisory lock, a race condition occurs. Two concurrent unauthenticated requests using different email addresses can both determine that no administrator exists, resulting in the creation of multiple User and InstanceAdmin rows. This allows an attacker to obtain instance-admin authority and share unrestricted administration privileges with the legitimate operator.
**Recommendations**
Update to version 1.4.0.