Junglewise Threat Intelligence

CVE-2026-59712: Leantime credential disclosure in JSON-RPC getUser API

CVE-2026-59712 · Severity: high · CVSS 8.1 · Published 2026-07-06

Technologies: Leantime. Vendors: Leantime.

Executive brief

Leantime, a project management system, contains a security flaw in its internal communication interface. An authorized user of the system can bypass security restrictions to view sensitive information about other users, including their encrypted passwords and two-factor authentication (2FA) codes. This could allow a malicious user to take over other accounts, including those of administrators, potentially leading to a full system compromise and data theft.

Technical details

A Broken Object Level Authorization (BOLA) vulnerability exists in Leantime's JSON-RPC API due to missing authorization checks in the Users::getUser method. The method is tagged as an API endpoint but lacks the #[RequiresPermission] attribute, causing the PermissionEnforcer to skip authorization. An authenticated attacker can supply arbitrary user IDs to the users.getUser method to retrieve the complete database row for any user. The returned data includes sensitive fields such as bcrypt password hashes, plaintext TOTP secrets, session tokens, and password reset tokens. This enables offline password cracking, 2FA bypass, and session hijacking. The issue is fixed in commit 4f2612d by stripping sensitive fields from the API response.

Affected products

  • Leantime Leantime <= 3.4.4

Timeline

  • 2026-06-13: disclosed: Initial report to vendor via email
  • 2026-06-20: other: Public issue opened on GitHub repository
  • 2026-07-04: patched: Fix committed to master branch
  • 2026-07-06: advisory: CVE published and NVD record created

References

Related threats