CVE-2026-92772 PUBLISHED

Leantime before 3.9.6 Unauthorized Plugin Installation via HTMX

Assigner: VulnCheck
Reserved: 16.09.2026 Published: 16.09.2026 Updated: 16.09.2026

Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks permission validation. Authenticated users with limited roles can install marketplace plugins and control arbitrary properties including identifier, version, and license key to deploy malicious plugins.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor Leantime
Product leantime
Versions Default: unaffected
  • affected from 0 to 3.9.6 (excl.)

Credits

  • George Chen finder

References

Problem Types

  • Missing Authorization CWE