Skip to content

Leantime vulnerabilities

3 CVEs tracked

The open-source project management solution Leantime appears in recent reporting with several critical vulnerabilities. Key events include unauthorized data access by authenticated users (CVE-2026-66412) and a Server-Side Request Forgery (SSRF) combined with Local File Inclusion (LFI) that could lead to remote code execution (CVE-2026-66415). Additionally, the presence of an Open Redirect vulnerability exploitable by unauthenticated attackers (CVE-2026-66414) poses a trust exploitation risk. Defenders should immediately update versions 3.6.2 and prior, and specifically monitor for suspicious requests targeting the `tickets.getMilestone` endpoint and the `Blueprints::import()` function.

Azərbaycanca: Leantime açıq mənbəli layihə idarəetmə həlli olaraq son hesabatlarda bir neçə kritik zəifliklə qeyd olunur. Əsas hadisələr autentifikasiya olunmuş istifadəçilər tərəfindən icazəsiz məlumat oxunması (CVE-2026-66412) və uzaqdan kod icrasına səbəb ola biləcək Server-Side Request Forgery (SSRF) və Local File Inclusion (LFI) zəifliyidir (CVE-2026-66415). Bundan əlavə, autentifikasiya olunmamış istifadəçilər üçün mövcud olan və etimadı istismar edən Open Redirect zəifliyi (CVE-2026-66414) də aşkarlanıb. Müdafiəçilər dərhal 3.6.2 və daha əvvəlki versiyaları yeniləməli, xüsusilə `tickets.getMilestone` endpoint-i və `Blueprints::import()` funksiyasına yönələn şübhəli sorğuları izləməlidir.

This vendor's CVEs3

This hub is built from skopnix's own reporting on Leantime: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.