CVE-2026-54418

HIGH

Leantime <= 3.6.2 TwoFA JSON-RPC - Cross-Account 2FA Bypass

Title source: manual
STIX 2.1

Description

Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable, and disable2FA, which act on a caller-supplied userId parameter with no ownership check, session pinning, or permission-attribute gate (unlike other RPC-exposed methods in the same dispatcher).

References (1)

Core 1
Core References

Scores

CVSS v3 8.1
EPSS 0.0025
EPSS Percentile 16.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-862
Status published
Products (1)
Leantime/Leantime < 3.6.2
Published Aug 05, 2026
Tracked Since Aug 05, 2026