CVE-2026-59712
HIGHLeantime - Credential Disclosure via Unauthenticated JSON-RPC users.getUser Method
Title source: cnaDescription
Leantime's Users::getUser method in the JSON-RPC API lacks proper authorization checks, allowing authenticated users to retrieve full user credential rows including password hashes, TOTP secrets, and session tokens. Attackers can exploit this by calling users.getUser with arbitrary user IDs to enumerate all accounts and obtain credentials for offline password cracking, 2FA bypass, and session hijacking.
References (4)
Core 4
Core References
Patch patch
Patch Commit
https://github.com/Leantime/leantime/commit/4f2612d13e0e8a2093092a846b44506cf133b671
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/leantime-credential-disclosure-via-unauthenticated-json-rpc-users-getuser-method
Scores
CVSS v3
8.1
EPSS
0.0025
EPSS Percentile
16.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-639
Status
published
Products (1)
Leantime/Leantime
< 3.4.4
Published
Jul 06, 2026
Tracked Since
Jul 07, 2026