Skip to content
Threat Feed

Vendor

Leantime

4 briefs RSS
high advisory

Authorization Bypass in Leantime HTMX Plugin Installation

Leantime versions prior to 3.9.6 contain an authorization bypass vulnerability in the HTMX plugin installation endpoint, allowing low-privileged authenticated users to deploy arbitrary plugins.

Leantime
1r 1c
high advisory

Leantime Authenticated LFI and SSRF via Blueprints

Leantime 3.6.2 contains a vulnerability in the Blueprints::import method allowing authenticated attackers to perform SSRF and LFI via the JSON-RPC API.

Leantime lfi ssrf cve-2026-66415 web-vulnerability csrf cve-2026-66416
1t 1c
high advisory

CVE-2026-59713: Leantime OIDC Login CSRF leading to Session Fixation

CVE-2026-59713 identifies a high-severity OIDC login Cross-Site Request Forgery (CSRF) vulnerability in Leantime's verifyState() method, allowing attackers to craft malicious callback URLs with attacker-controlled authorization codes to perform session fixation and log victims into an attacker's session.

Leantime csrf oidc session-fixation web-application vulnerability
3t 1c
high advisory

CVE-2026-59712: Leantime JSON-RPC API Authorization Bypass Leads to Credential Disclosure

An authenticated user can exploit CVE-2026-59712, an authorization bypass vulnerability in Leantime's JSON-RPC API `Users::getUser` method, to retrieve sensitive user credential information including password hashes, TOTP secrets, and session tokens for any user, leading to account enumeration, offline password cracking, 2FA bypass, and session hijacking.

Leantime authorization-bypass credential-disclosure api-exploitation web-vulnerability cve
3t 1c 3i