ZeroHour

CVE-2026-92772

moderate

Authorization Bypass in Leantime Lets Low-Privilege Users Install Malicious Plugins

CVSS 4.0
7.1 high
EPSS
Published
()
Modified
AI analysis

Leantime before 3.9.6 contains an authorization bypass (CWE-862) in its HTMX plugin install endpoint, which lacks permission validation. Any authenticated user with a limited or low-privilege role can call this network-reachable endpoint and install plugins from the marketplace, fully controlling arbitrary properties including the plugin identifier, version, and license key. By abusing this, an attacker can deploy a malicious or attacker-controlled plugin onto the server, compromising the integrity of the installation (CVSS 4.0: 7.1 High, network vector, low privileges, no user interaction). All Leantime deployments running a version earlier than 3.9.6 that host low-privileged user accounts are affected. No public proof-of-concept or in-the-wild exploitation is known, and the issue is not listed in CISA KEV.

What to do: Upgrade Leantime to version 3.9.6 or later, which adds the missing permission validation on the plugin install endpoint. Until patched, review which low-privileged users hold accounts on the instance and audit the installed plugin list for unrecognized identifiers, versions, or license keys. Limit network exposure of the Leantime instance to trusted users as an interim mitigation.

Affected
Leantimeall versions before 3.9.6
Estimated exposure
moderatelow thousands of self-hosted instances (est.), of which only a fraction are internet-exposed — Leantime is a self-hosted, open-source project management server typically deployed once per organization with a modest community footprint (thousands of GitHub stars), suggesting total installations in the low thousands to tens of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks permission validation. Authenticated users with limited roles can install marketplace plugins and control arbitrary properties including identifier, version, and license key to deploy malicious plugins.

Weakness
CWE-862
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.