Impact
The vulnerability exposes an improper authorization flaw in the Leantime JSON‑RPC Endpoint’s addUser function that allows a remote attacker to supply a manipulated role argument and thereby elevate their privileges beyond what is intended. By assigning themselves an owner or admin role, an attacker can gain full control of the application, accessing sensitive data, modifying project settings, and potentially disrupting operations.
Affected Systems
All Leantime releases up to and including version 3.8.0 are affected. The flaw exists across all deployments of these versions and there is currently no vendor‑supplied patch or updated release containing a fix.
Risk and Exploitability
The CVSS score is 5.3, indicating moderate severity, while the EPSS score is less than 1 %, suggesting a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires remote access to the JSON‑RPC endpoint, which is typically reachable unless network controls are implemented.
OpenCVE Enrichment