Broken Access Control in Leantime Product by Leantime
CVE-2026-66412
7.1HIGH
What is CVE-2026-66412?
Leantime versions 3.6.2 and earlier contain a broken access control vulnerability that permits authenticated users to read milestone data from projects they are not assigned to. By supplying arbitrary integer milestone IDs to the tickets.getMilestone JSON-RPC endpoint, attackers can exploit this vulnerability to enumerate these IDs and gain unauthorized access to sensitive project planning information, including milestone titles, descriptions, and timelines across all projects within the instance, irrespective of their membership status.
Affected Version(s)
Leantime 0 <= 3.6.2
