PT-2026-106038 · Plane · Plane
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Plane versions 0.13 through 1.3.x
Description
An issue exists in the
InstanceAdminSignUpEndpoint within apps/api/plane/license/api/views/admin.py where the system uses InstanceAdmin.objects.first() to verify if an administrator already exists. Because account creation is performed without an atomic transaction, row lock, uniqueness guard, or advisory lock, a race condition occurs. Two concurrent unauthenticated requests using different email addresses can both determine that no administrator exists, resulting in the creation of multiple User and InstanceAdmin rows. This allows an attacker to obtain instance-admin authority and share unrestricted administration privileges with the legitimate operator.Recommendations
Update to version 1.4.0.
Exploit
Fix
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Plane