Cross-Site Request Forgery Vulnerability in Leantime by Leantime
CVE-2026-66416
8.6HIGH
What is CVE-2026-66416?
Leantime 3.6.2 is impacted by a cross-site request forgery vulnerability that allows unauthenticated attackers to execute state-changing actions on behalf of authenticated users. This vulnerability arises from the exclusion of the Laravel VerifyCsrfToken middleware from the global middleware stack in the app/Http/Kernel.php file. By crafting malicious pages, attackers can leverage phishing emails or compromised websites to initiate unauthorized POST, PUT, and DELETE requests. This can lead to critical actions such as creating or deleting projects, modifying settings, and altering permissions under the guise of authenticated users, thereby posing a significant security risk.
Affected Version(s)
Leantime 0
