CVE-2026-54418 | Leantime up to 3.6.2 TwoFA Service userId improper authorization
A vulnerability categorized as critical has been discovered in Leantime up to 3.6.2. Affected by this vulnerability is the function leantime.rpc.TwoFA.TwoFA.getSetupData/leantime.rpc.TwoFA.TwoFA.saveSecret/leantime.rpc.TwoFA.TwoFA.verifyAndEnable/leantime.rpc.TwoFA.TwoFA.disable2FA of the component TwoFA Service. The manipulation of the argument userId results in improper authorization.
This vulnerability is known as CVE-2026-54418. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More