GHSA-p3jw-q4jg-x8w9HighCVSS 6.5

Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated...

Published
July 27, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (1)

📋 Description

Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated users to read milestone data from projects they are not assigned to by supplying arbitrary integer milestone IDs to the tickets.getMilestone JSON-RPC endpoint. Attackers can enumerate integer milestone IDs through the JSON-RPC API to access project planning information, milestone titles, descriptions, and timelines across all projects on the instance regardless of project membership.

🔗 References (6)