HIGH 7.1 NVD

CVE-2026-92772

Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks permission validation. Authenticated users w

Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks permission validation. Authenticated users with limited roles can install marketplace plugins and control arbitrary properties including identifier, version, and license key to deploy malicious plugins.

References

Published: 2026-09-16 · Source: NVD · Feed updated: 2026-09-16
This high severity vulnerability with a CVSS score of 7.1 was published on 2026-09-16 via NVD.
vulnfeed aggregates 14597 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.