CVE-2026-15509 | Leantime up to 3.8.0 JSON-RPC Endpoint editUser/addUser role improper authorization
A vulnerability was found in Leantime up to 3.8.0. It has been classified as critical. This impacts the function editUser/addUser of the component JSON-RPC Endpoint. The manipulation of the argument role leads to improper authorization.
This vulnerability is uniquely identified as CVE-2026-15509. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More