editOwn High · 8.8
Leantime JSON-RPC Account Takeover: Any Logged-In User Could Reset Anyone's Password
Leantime's self-service profile method was reachable over JSON-RPC with a caller-supplied user id and no ownership check. Any authenticated account, including a read-only one, could set a known password on the instance owner and log in as them. CVSS 8.8 High, 9.8 with self-registration. Fixed in v3.9.0. CVE-2026-76647. Found by Voke Cyber, coordinated via CERT/CC (VU#685483).