CVE-2026-66412: Leantime all versions prior to and 3.6.2 Broken Access Control via tickets.getMilestone JSON-RPC
Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated users to read milestone data from projects they are not assigned to by supplying arbitrary integer milestone IDs to the tickets.getMilestone JSON-RPC endpoint. Attackers can enumerate integer milestone IDs through the JSON-RPC API to access project planning information, milestone titles, descriptions, and timelines across all projects on the instance regardless of project membership.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Leantimeto a version that resolves this vulnerability.Fixed in 3.6.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch Leantime all versions prior to and 3.6.2 Broken Access Control via tickets.getMilestone JSON-RPC
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66412?
CVE-2026-66412 has a medium severity score of 6.5.
What is the impact of CVE-2026-66412?
CVE-2026-66412 allows authenticated users to access milestone data from unauthorized projects due to broken access control.
How do I fix CVE-2026-66412?
To fix CVE-2026-66412, update to Leantime version 3.6.2 or later.
Who is affected by CVE-2026-66412?
All versions of Leantime prior to 3.6.2 are affected by CVE-2026-66412.
What component is vulnerable in CVE-2026-66412?
The vulnerable component in CVE-2026-66412 is the tickets.getMilestone JSON-RPC endpoint.