<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Leantime (&lt; 3.9.6) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/leantime--3.9.6/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 16 Sep 2026 21:55:42 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/leantime--3.9.6/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in Leantime HTMX Plugin Installation</title><link>https://feed.craftedsignal.io/briefs/2026-09-leantime-auth-bypass/</link><pubDate>Wed, 16 Sep 2026 21:55:42 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-leantime-auth-bypass/</guid><description>Leantime versions prior to 3.9.6 contain an authorization bypass vulnerability in the HTMX plugin installation endpoint, allowing low-privileged authenticated users to deploy arbitrary plugins.</description><content:encoded><![CDATA[<p>Leantime versions prior to 3.9.6 are susceptible to an authorization bypass vulnerability (CVE-2026-92772) located within the HTMX plugin installation endpoint. The application fails to properly validate the permissions of users attempting to access the plugin installation interface. As a result, an authenticated user with limited role-based access can successfully interact with this endpoint to install marketplace plugins. An attacker can manipulate configuration properties, including plugin identifiers, versions, and license keys, to force the application to install unauthorized or malicious code. This vulnerability poses a significant risk to organizations as it enables attackers to move from a low-privileged account to achieving arbitrary code execution or persistence within the application environment. Defenders should prioritize patching Leantime to version 3.9.6 or later to enforce correct access control checks on the HTMX plugin installation process.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthorized users to deploy arbitrary plugins, leading to potential remote code execution, unauthorized data access, and persistent backdoors within the Leantime environment. This affects all organizations using Leantime versions earlier than 3.9.6 that permit standard user account creation or have exposed the application to untrusted internal actors.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Patch Leantime to version 3.9.6 or later immediately to resolve CVE-2026-92772.</li>
<li>Audit application logs for unauthorized plugin installation requests, specifically monitoring access to the HTMX plugin installation endpoint for users without administrative privileges.</li>
<li>Review existing plugin manifests to ensure no unauthorized or unrecognized plugins have been installed within the environment.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>