high · CVSS v3 7.1 · CVSS v4 7.1
CVE-2026-92772
Leantime versions prior to 3.9.6 contain an authorization bypass vulnerability in the HTMX plugin installation endpoint. Due to missing perm
Overview
Leantime versions prior to 3.9.6 contain an authorization bypass vulnerability in the HTMX plugin installation endpoint. Due to missing permission validation, authenticated users with low-level privileges can install arbitrary marketplace plugins and manipulate installation parameters. Updating to version 3.9.6 resolves the issue by enforcing strict permission checks.
Description
Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks permission validation. Authenticated users with limited roles can install marketplace plugins and control arbitrary properties including identifier, version, and license key to deploy malicious plugins.
Impact
Authenticated users with restricted roles can bypass authorization checks to install arbitrary plugins. This compromises system integrity and confidentiality, and could lead to server compromise if a malicious plugin is deployed.
Remediation
Update Leantime to version 3.9.6 or later. Restrict network access to management interfaces where applicable and audit currently installed plugins to ensure no unauthorized extensions were deployed prior to patching.
Risk context
Assigned a CVSS score of 7.1 (High). While authentication is required to trigger the vulnerability, low-privileged users can exploit missing authorization checks to perform administrative actions.
Affected products
- Leantime Leantime (< 3.9.6)
Scores
- Severity
- high
- CVSS v2
- 7.5
- CVSS v3
- 7.1
- CVSS v4
- 7.1
- EPSS
- —