PT-2026-66545 · Leantime · Leantime

·

CVE-2026-66416

·

Published

2026-07-30

·

Updated

2026-07-31

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Leantime version 3.6.2
Description An issue exists where the Laravel VerifyCsrfToken middleware is excluded from the global middleware stack in app/Http/Kernel.php. This allows unauthenticated attackers to perform state-changing actions on behalf of authenticated users by crafting malicious pages delivered via phishing emails or websites. This can trigger unauthorized POST, PUT, and DELETE requests to create or delete projects, modify settings, and change permissions. Cross-site request forgery is a type of attack that forces an authenticated user to execute unwanted actions on a web application.
Recommendations Update Leantime to a version newer than 3.6.2.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66416
GHSA-X8VX-9G5W-W5RR

Affected Products

Leantime