Broken Access Control in Leantime Product by Leantime
CVE-2026-66412

7.1HIGH

Key Information:

Vendor

Leantime

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-66412?

Leantime versions 3.6.2 and earlier contain a broken access control vulnerability that permits authenticated users to read milestone data from projects they are not assigned to. By supplying arbitrary integer milestone IDs to the tickets.getMilestone JSON-RPC endpoint, attackers can exploit this vulnerability to enumerate these IDs and gain unauthorized access to sensitive project planning information, including milestone titles, descriptions, and timelines across all projects within the instance, irrespective of their membership status.

Affected Version(s)

Leantime 0 <= 3.6.2

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Javokhir Tursunboyev (@javokhir-sec)
.