JSON-RPC Method Vulnerability in Leantime Product by Leantime
CVE-2026-54418
8.1HIGH
What is CVE-2026-54418?
Leantime versions up to 3.6.2 are vulnerable due to inadequate access control in specific JSON-RPC methods. Authenticated users can manipulate RPC endpoints like getSetupData to access sensitive information, such as another user's TOTP secret, or disable two-factor authentication for other accounts. This oversight can lead to significant unauthorized access, as it circumvents established two-factor authentication protections, highlighting the necessity for stricter session controls and owner checks in the application’s design.
Affected Version(s)
Leantime 0 <= 3.6.2
