{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/leantime--3.9.6/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:leantime:leantime:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-92772"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Leantime (\u003c 3.9.6)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Leantime"],"content_html":"\u003cp\u003eLeantime versions prior to 3.9.6 are susceptible to an authorization bypass vulnerability (CVE-2026-92772) located within the HTMX plugin installation endpoint. The application fails to properly validate the permissions of users attempting to access the plugin installation interface. As a result, an authenticated user with limited role-based access can successfully interact with this endpoint to install marketplace plugins. An attacker can manipulate configuration properties, including plugin identifiers, versions, and license keys, to force the application to install unauthorized or malicious code. This vulnerability poses a significant risk to organizations as it enables attackers to move from a low-privileged account to achieving arbitrary code execution or persistence within the application environment. Defenders should prioritize patching Leantime to version 3.9.6 or later to enforce correct access control checks on the HTMX plugin installation process.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthorized users to deploy arbitrary plugins, leading to potential remote code execution, unauthorized data access, and persistent backdoors within the Leantime environment. This affects all organizations using Leantime versions earlier than 3.9.6 that permit standard user account creation or have exposed the application to untrusted internal actors.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch Leantime to version 3.9.6 or later immediately to resolve CVE-2026-92772.\u003c/li\u003e\n\u003cli\u003eAudit application logs for unauthorized plugin installation requests, specifically monitoring access to the HTMX plugin installation endpoint for users without administrative privileges.\u003c/li\u003e\n\u003cli\u003eReview existing plugin manifests to ensure no unauthorized or unrecognized plugins have been installed within the environment.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T21:55:42Z","date_published":"2026-09-16T21:55:42Z","id":"https://feed.craftedsignal.io/briefs/2026-09-leantime-auth-bypass/","summary":"Leantime versions prior to 3.9.6 contain an authorization bypass vulnerability in the HTMX plugin installation endpoint, allowing low-privileged authenticated users to deploy arbitrary plugins.","title":"Authorization Bypass in Leantime HTMX Plugin Installation","url":"https://feed.craftedsignal.io/briefs/2026-09-leantime-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Leantime (\u003c 3.9.6)","version":"https://jsonfeed.org/version/1.1"}