CVE-2026-54418

EUVD-2026-53193
Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable, and disable2FA, which act on a caller-supplied userId parameter with no ownership check, session pinning, or permission-attribute gate (unlike other RPC-exposed methods in the same dispatcher).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
TuranSecCNA
8.1 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 16.41%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
leantimeleantime
𝑥
≤ 3.6.2
CNA