CVE-2026-66415 | Leantime up to 3.6.1 Blueprint Import Blueprints::import server-side request forgery (ID 3656)

SecurityVulns

A vulnerability, which was classified as problematic, has been found in Leantime up to 3.6.1. Affected is the function Blueprints::import of the component Blueprint Import. This manipulation causes server-side request forgery.

The identification of this vulnerability is CVE-2026-66415. It is possible to initiate the attack remotely. There is no exploit available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More