{"id":"CVE-2026-54418","published":"2026-08-05T08:16:33.777","lastModified":"2026-08-10T12:17:18.100","description":"Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable, and disable2FA, which act on a caller-supplied userId parameter with no ownership check, session pinning, or permission-attribute gate (unlike other RPC-exposed methods in the same dispatcher).","cvssScore":8.1,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","cwes":["CWE-862"],"vendors":[],"products":[],"references":[{"url":"https://github.com/Leantime/leantime","tags":[]}],"exploitRefs":[{"url":"https://github.com/Leantime/leantime","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows unauthorized access to TwoFA management functions without proper authentication or permission checks, posing a significant security risk.","exploitability":"Exploitation requires knowledge of the userId and could be moderately difficult due to potential session management mechanisms in place.","blast_radius":"If exploited, it could lead to full control over two-factor authentication settings for affected users.","remediation":"Update to the latest version of Leantime that addresses this vulnerability or implement strict access controls for TwoFA management functions.","tags":["auth-bypass","web","permissions"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:50:17.042Z"}}