Cross-Site Request Forgery Vulnerability in Leantime by Leantime
CVE-2026-66416

8.6HIGH

Key Information:

Vendor

Leantime

Status
Vendor
CVE Published:
30 July 2026

What is CVE-2026-66416?

Leantime 3.6.2 is impacted by a cross-site request forgery vulnerability that allows unauthenticated attackers to execute state-changing actions on behalf of authenticated users. This vulnerability arises from the exclusion of the Laravel VerifyCsrfToken middleware from the global middleware stack in the app/Http/Kernel.php file. By crafting malicious pages, attackers can leverage phishing emails or compromised websites to initiate unauthorized POST, PUT, and DELETE requests. This can lead to critical actions such as creating or deleting projects, modifying settings, and altering permissions under the guise of authenticated users, thereby posing a significant security risk.

Affected Version(s)

Leantime 0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Javokhir Tursunboyev (@javokhir-sec)
.