What is CVE-2026-76647?
A missing authorization vulnerability was found in Leantime's JSON-RPC API through version 3.9.0. This flaw allows an authenticated user to invoke unauthorized service-layer methods via the JSON-RPC dispatcher, users should immediately update to the latest patched version.
Azərbaycanca: Leantime açıq-qaynaq layihə idarəetmə alətinin 3.9.0 və daha əvvəl versiyalarında JSON-RPC API-də autorizasiya çatışmazlığı aşkarlanıb. Bu boşluq autentifikasiya olunmuş istifadəçiyə icazəsiz xidmət metodlarını çağırmağa imkan verir, istifadəçilər dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the Leantime open-source project management tool are vulnerable to CVE-2026-76647?
Leantime versions 3.9.0 and earlier are affected by this vulnerability.
Does an attacker need to be authenticated to exploit CVE-2026-76647?
Yes, this flaw allows an authenticated user to invoke unauthorized service-layer methods via the JSON-RPC API.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.