What is CVE-2026-66415?
CVE-2026-66415 is a combined Server-Side Request Forgery (SSRF) and Local File Inclusion (LFI) vulnerability in Leantime 3.6.2, where an authenticated attacker can read internal resources via unsanitized user-supplied filenames passed to file_get_contents() in the Blueprints::import() method. Users should immediately update to the latest patched version of Leantime.
Azərbaycanca: Leantime 3.6.2 versiyasında aşkarlanan CVE-2026-66415 zəifliyi, autentifikasiya olunmuş hücumçuya Blueprints::import() metodunda fayl yollarının yoxlanılmaması səbəbindən 'file_get_contents()' vasitəsilə daxili resursları oxumağa imkan verən Server-Side Request Forgery (SSRF) və Local File Inclusion (LFI) problemidir. İstifadəçilər dərhal Leantime proqramını ən son versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which version of Leantime is affected by CVE-2026-66415?
This vulnerability was discovered in Leantime version 3.6.2.
Does exploiting CVE-2026-66415 require the attacker to be authenticated?
Yes, this vulnerability can be exploited by an authenticated attacker.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.