CVE-2026-66416
HIGHLeantime CSRF Protection Globally Disabled by Omission of Laravel VerifyCsrfToken Middleware
Title source: cnaDescription
Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perform state-changing actions on behalf of authenticated users by excluding the Laravel VerifyCsrfToken middleware from the global middleware stack in app/Http/Kernel.php. Attackers can craft malicious pages delivered via phishing emails or malicious websites to trigger unauthorized POST, PUT, and DELETE requests that create or delete projects, modify settings, and change permissions as any authenticated user.
References (4)
Core 4
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory
https://github.com/javokhir-sec/CVE-PoC-Hub/security/advisories/GHSA-x8vx-9g5w-w5rr
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/leantime-csrf-protection-globally-disabled-by-omission-of-laravel-verifycsrftoken-middleware
Scores
CVSS v3
8.8
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-352
Status
published
Products (1)
Leantime/Leantime
< 3.6.2
Published
Jul 30, 2026
Tracked Since
Jul 30, 2026