rootpwn

high · CVSS v3 7.1 · CVSS v4 7.1

CVE-2026-92772

Leantime versions prior to 3.9.6 contain an authorization bypass vulnerability in the HTMX plugin installation endpoint. Due to missing perm

Overview

Leantime versions prior to 3.9.6 contain an authorization bypass vulnerability in the HTMX plugin installation endpoint. Due to missing permission validation, authenticated users with low-level privileges can install arbitrary marketplace plugins and manipulate installation parameters. Updating to version 3.9.6 resolves the issue by enforcing strict permission checks.

Description

Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks permission validation. Authenticated users with limited roles can install marketplace plugins and control arbitrary properties including identifier, version, and license key to deploy malicious plugins.

Impact

Authenticated users with restricted roles can bypass authorization checks to install arbitrary plugins. This compromises system integrity and confidentiality, and could lead to server compromise if a malicious plugin is deployed.

Remediation

Update Leantime to version 3.9.6 or later. Restrict network access to management interfaces where applicable and audit currently installed plugins to ensure no unauthorized extensions were deployed prior to patching.

Risk context

Assigned a CVSS score of 7.1 (High). While authentication is required to trigger the vulnerability, low-privileged users can exploit missing authorization checks to perform administrative actions.

Affected products

  • Leantime Leantime (< 3.9.6)

Scores

Severity
high
CVSS v2
7.5
CVSS v3
7.1
CVSS v4
7.1
EPSS

Leantime Authorization Bypass Broken Access Control Plugin Management Patch Required CVE-2026-92772

← All CVEs