


Perceptive Security
SOC/SIEM Consultancy

Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable, and disable2FA, which act on a caller-su…
Published:
4 augustus 2026 om 22:00:00
Alert date:
5 augustus 2026 om 09:07:41
Source:
nvd.nist.gov
Identity & Access, Web Technologies, Enterprise Applications
Leantime versions through 3.6.2 expose multiple JSON-RPC methods related to two-factor authentication (getSetupData, saveSecret, verifyAndEnable, disable2FA) without proper authorization controls. These methods accept a caller-supplied userId parameter with no ownership verification, session pinning, or permission gating. Any authenticated user can exploit this to read another user's live TOTP secret or completely disable 2FA on any account, fully defeating 2FA protections. This vulnerability is related to CVE-2026-15509, which covers a similar missing-authorization flaw in the JSON-RPC editUser/addUser role-assignment endpoints in the same application. The two vulnerabilities are distinct and independently fixable. The lack of access control on sensitive authentication management endpoints represents a critical security gap in account-level protection.
Technical details
Mitigation steps:
Affected products:
Leantime 3.6.2
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
