What is CVE-2026-66412?
CVE-2026-66412 is a broken access control vulnerability in Leantime 3.6.2 and prior that allows authenticated users to read milestone data from projects they are not assigned to via the `tickets.getMilestone` JSON-RPC endpoint by supplying arbitrary integer milestone IDs. Affected systems should be updated to the latest version immediately.
Azərbaycanca: CVE-2026-66412, Leantime 3.6.2 və əvvəlki versiyalarda autentifikasiya olunmuş istifadəçilərə aid olmadıqları layihələrin mərhələ məlumatlarını oxumağa imkan verən broken access control zəifliyidir. Bu, `tickets.getMilestone` JSON‑RPC endpoint‑inə ixtiyari tam ədəd milestone ID‑ləri göndərməklə həyata keçirilir. Təsirə məruz qalan sistemlərin dərhal ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which function is affected by the CVE-2026-66412 vulnerability in Leantime?
The vulnerability affects the `tickets.getMilestone` JSON-RPC endpoint.
Does exploiting CVE-2026-66412 in Leantime 3.6.2 require authentication?
Yes, the vulnerability can be exploited by authenticated users.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.