CVE-2026-92772
moderateAuthorization Bypass in Leantime Lets Low-Privilege Users Install Malicious Plugins
Leantime before 3.9.6 contains an authorization bypass (CWE-862) in its HTMX plugin install endpoint, which lacks permission validation. Any authenticated user with a limited or low-privilege role can call this network-reachable endpoint and install plugins from the marketplace, fully controlling arbitrary properties including the plugin identifier, version, and license key. By abusing this, an attacker can deploy a malicious or attacker-controlled plugin onto the server, compromising the integrity of the installation (CVSS 4.0: 7.1 High, network vector, low privileges, no user interaction). All Leantime deployments running a version earlier than 3.9.6 that host low-privileged user accounts are affected. No public proof-of-concept or in-the-wild exploitation is known, and the issue is not listed in CISA KEV.
What to do: Upgrade Leantime to version 3.9.6 or later, which adds the missing permission validation on the plugin install endpoint. Until patched, review which low-privileged users hold accounts on the instance and audit the installed plugin list for unrecognized identifiers, versions, or license keys. Limit network exposure of the Leantime instance to trusted users as an interim mitigation.
| Leantime | all versions before 3.9.6 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks permission validation. Authenticated users with limited roles can install marketplace plugins and control arbitrary properties including identifier, version, and license key to deploy malicious plugins.
- Weakness
- CWE-862
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.