{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-66416/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.5,"id":"CVE-2026-66415"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Leantime (3.6.2)"],"_cs_severities":["high"],"_cs_tags":["leantime","lfi","ssrf","cve-2026-66415","web-vulnerability","csrf","cve-2026-66416"],"_cs_type":"advisory","_cs_vendors":["Leantime"],"content_html":"\u003cp\u003eLeantime version 3.6.2 is susceptible to a combined server-side request forgery (SSRF) and local file inclusion (LFI) vulnerability stemming from improper input validation. The vulnerability exists within the Blueprints::import() method, which utilizes the user-supplied filename parameter directly within the PHP file_get_contents() function without sufficient sanitization or path validation. An authenticated attacker can exploit this flaw by submitting a crafted JSON-RPC API request containing path traversal sequences (such as ../) or URL wrappers (like file:// or http://).\u003c/p\u003e\n\u003cp\u003eThis issue allows an attacker to bypass intended access controls to read sensitive files from the underlying server filesystem, such as configuration files, or to conduct SSRF attacks to target internal services and cloud metadata endpoints. Because the vulnerability is reachable through the application's JSON-RPC API, any authenticated user - including those with low-privileged accounts - can escalate their access to extract system information or perform internal reconnaissance, potentially leading to full system compromise depending on the server configuration.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows authenticated attackers to perform arbitrary file reads or pivot into internal network infrastructure. This vulnerability poses a significant risk to organizations hosting Leantime in cloud environments, where attackers may retrieve metadata credentials. Unauthorized access to system configuration files may lead to the exposure of database credentials, encryption keys, and other secrets, facilitating further exploitation or data exfiltration.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade Leantime instances to the latest secure version immediately to remediate CVE-2026-66415.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation and sanitization for all parameters passed to file-system related functions in the application code.\u003c/li\u003e\n\u003cli\u003eRestrict access to the JSON-RPC API to trusted users and monitor API logs for anomalous requests containing path traversal characters or URL protocols.\u003c/li\u003e\n\u003cli\u003eEnforce principle of least privilege for the service account running the Leantime application to limit the scope of potential file access.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-07-30T19:31:03Z","date_published":"2026-07-30T19:30:56Z","id":"https://feed.craftedsignal.io/briefs/2026-07-leantime-lfi-ssrf/","summary":"Leantime 3.6.2 contains a vulnerability in the Blueprints::import method allowing authenticated attackers to perform SSRF and LFI via the JSON-RPC API.","title":"Leantime Authenticated LFI and SSRF via Blueprints","url":"https://feed.craftedsignal.io/briefs/2026-07-leantime-lfi-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-66416","version":"https://jsonfeed.org/version/1.1"}