top of page
perceptive_background_267k.jpg

Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable, and disable2FA, which act on a caller-su…

Published:

4 augustus 2026 om 22:00:00

Alert date:

5 augustus 2026 om 09:07:41

Source:

nvd.nist.gov

Click to open the original link from this advisory

Identity & Access, Web Technologies, Enterprise Applications

Leantime versions through 3.6.2 expose multiple JSON-RPC methods related to two-factor authentication (getSetupData, saveSecret, verifyAndEnable, disable2FA) without proper authorization controls. These methods accept a caller-supplied userId parameter with no ownership verification, session pinning, or permission gating. Any authenticated user can exploit this to read another user's live TOTP secret or completely disable 2FA on any account, fully defeating 2FA protections. This vulnerability is related to CVE-2026-15509, which covers a similar missing-authorization flaw in the JSON-RPC editUser/addUser role-assignment endpoints in the same application. The two vulnerabilities are distinct and independently fixable. The lack of access control on sensitive authentication management endpoints represents a critical security gap in account-level protection.

Technical details

Mitigation steps:

Affected products:

Leantime 3.6.2

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page