PT-2026-56014 · Leantime · Leantime

·

CVE-2026-59712

·

Published

2026-07-06

·

Updated

2026-07-07

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Leantime (affected versions not specified)
Description The Users::getUser() function within the JSON-RPC API does not implement sufficient authorization checks. This allows authenticated users to retrieve complete user credential records by providing arbitrary user IDs. The exposed data includes password hashes, TOTP (Time-based One-Time Password) secrets, and session tokens, which can be used for account enumeration, offline password cracking, bypassing two-factor authentication, and session hijacking.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59712

Affected Products

Leantime