Description
Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks permission validation. Authenticated users with limited roles can install marketplace plugins and control arbitrary properties including identifier, version, and license key to deploy malicious plugins.
Published: 2026-09-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Leantime prior to version 3.9.6 contains an authorization bypass in the HTMX plugin install endpoint. The endpoint accepts metadata such as plugin identifier, version, and license key without validating the caller’s role. A logged‑in user with a limited role can therefore register and activate arbitrary marketplace plugins, effectively installing code of the attacker’s choosing and achieving full control of the application instance.

Affected Systems

Any deployment of Leantime older than 3.9.6 is affected. The vulnerability resides in the Leantime application and is identified under the vendor product Leantime:Leantime. Users must verify that they are running version 3.9.6 or newer to avoid exposure.

Risk and Exploitability

The CVSS score of 7.1 places this issue in the high severity range. The EPSS score is below 1%, indicating low current exploitation probability, and the vulnerability is not listed in CISA KEV. The attack requires an authenticated user with a non‑admin role to send a crafted request to the HTMX plugin install endpoint. Successful exploitation leads to arbitrary code execution under the application’s privileges. The risk is internal, stemming from insufficient permission checks, and can result in complete compromise of the affected instance.

Generated by OpenCVE AI on September 17, 2026 at 22:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Leantime 3.9.6 or newer, where the authorization check is enforced.
  • If an upgrade is not immediately possible, disable the HTMX plugin installation endpoint or block it at the web‑server level.
  • Review and restrict role permissions so that only administrators can invoke the plugin install endpoint.

Generated by OpenCVE AI on September 17, 2026 at 22:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks permission validation. Authenticated users with limited roles can install marketplace plugins and control arbitrary properties including identifier, version, and license key to deploy malicious plugins.
Title Leantime before 3.9.6 Unauthorized Plugin Installation via HTMX
First Time appeared Leantime
Leantime leantime
Weaknesses CWE-862
CPEs cpe:2.3:a:leantime:leantime:*:*:*:*:*:*:*:*
Vendors & Products Leantime
Leantime leantime
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Leantime Leantime
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T14:52:22.912Z

Reserved: 2026-09-16T19:15:39.017Z

Link: CVE-2026-92772

cve-icon Vulnrichment

Updated: 2026-09-17T14:52:17.025Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T21:17:25.897

Modified: 2026-09-17T15:16:59.167

Link: CVE-2026-92772

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T22:45:06Z

Weaknesses