Leantime · Leantime · CVE-2026-59712
**Name of the Vulnerable Software and Affected Versions**
Leantime (affected versions not specified)
**Description**
The `Users::getUser()` function within the JSON-RPC API does not implement sufficient authorization checks. This allows authenticated users to retrieve complete user credential records by providing arbitrary user IDs. The exposed data includes password hashes, TOTP (Time-based One-Time Password) secrets, and session tokens, which can be used for account enumeration, offline password cracking, bypassing two-factor authentication, and session hijacking.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.