CVE-2026-54418
HIGHLeantime <= 3.6.2 TwoFA JSON-RPC - Cross-Account 2FA Bypass
Title source: manualDescription
Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable, and disable2FA, which act on a caller-supplied userId parameter with no ownership check, session pinning, or permission-attribute gate (unlike other RPC-exposed methods in the same dispatcher).
References (1)
Core 1
Core References
third-party-advisory
https://github.com/Leantime/leantime
Scores
CVSS v3
8.1
EPSS
0.0025
EPSS Percentile
16.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-862
Status
published
Products (1)
Leantime/Leantime
< 3.6.2
Published
Aug 05, 2026
Tracked Since
Aug 05, 2026