Security Research

Vulnerabilities we have found and responsibly disclosed in widely used software. Original research, coordinated disclosure, and the CVEs that come out of it.

LEANTIME
editOwn
High · 8.8
Leantime · Account Takeover · Fixed

Leantime JSON-RPC Account Takeover: Any Logged-In User Could Reset Anyone's Password

Leantime's self-service profile method was reachable over JSON-RPC with a caller-supplied user id and no ownership check. Any authenticated account, including a read-only one, could set a known password on the instance owner and log in as them. CVSS 8.8 High, 9.8 with self-registration. Fixed in v3.9.0. CVE-2026-76647. Found by Voke Cyber, coordinated via CERT/CC (VU#685483).

CVE-2026-
16772
High · 8.1
Akaunting · Privilege Escalation · Fixed

CVE-2026-16772 — Privilege Escalation to Admin in Akaunting via Self-Service Profile Update

When an Akaunting user saves their own profile, the update applies the submitted list of roles with no check on whether that user may assign roles. Any account with the default self-service permission — which ordinary employee and accountant roles hold — can add the admin role to itself and take full control of the company's books. CVSS 8.1 High, fixed in 3.2.0. Found by Voke Cyber, disclosed via CERT/CC (VU#737420).

CVE-2026-
17613
High · 7.5
Penpot · File Takeover · No Fix

CVE-2026-17613 — Cross-Team File Takeover in Penpot via import-binfile

Penpot's file-import API accepts a caller-supplied file-id and never checks it belongs to you. Any logged-in user can overwrite any file on the instance — and the import re-parents it into the attacker's project, handing them ownership of the victim's design. CVSS 7.5 High (6.5 where self-registration is closed), no patch. Found by Voke Cyber, disclosed via CERT/CC (VU#241166).

CVE-2026-
16751
Medium · 6.5
Ente · Account Takeover · Fixed

CVE-2026-16751 — Account Takeover in Ente via Emergency-Contact Recovery Bypass

Ente's emergency-recovery approval endpoint never checked the recovery session belonged to the caller. A former emergency contact could skip the 30-day waiting period in one request, reset the victim's password, and seize the account — encrypted photos, Ente Auth 2FA seeds, and Locker secrets — in under a minute. CVSS 6.5. Found by Voke Cyber; fixed in PR #11311.

CVE-2026-
16624
Critical · 9.6
Cal.com · Authorization Bypass · No Fix

Cal.com Cross-Tenant Webhook Plant — Authorization Bypass via Unvalidated teamId

Cal.com's webhook-create API never checks that you belong to the teamId you supply. Any authenticated user can attach a webhook to any team by its numeric id and copy every booking — attendee name, email, phone, and the video-call URL and password — to an attacker URL. CVSS 9.6 Critical (CVE-2026-16624), no patch. Found by Voke Cyber, disclosed via CERT/CC.

CVE-2026-
15630
Critical · 9.9
Casdoor · Authorization Bypass · No Fix

CVE-2026-15630 — Cross-Tenant Authorization Bypass in Casdoor IAM

Casdoor's authorization filter checks the URL ?id= while the controllers act on the JSON body. Any organization admin can reach every other tenant on the instance — delete its users, plant a backdoor admin, wipe its SSO certs, or escalate to global admin. CVSS 9.9 Critical, no patch. Found by Voke Cyber, disclosed via CERT/CC (VU#889462).

CVE-2026-
39878
Critical · 9.3
Chamilo LMS · Stored XSS

CVE-2026-39878 — Unauthenticated Stored XSS to Admin Takeover in Chamilo LMS

A stored XSS (CWE-79) in Chamilo's self-registration form. A null byte hidden inside an event handler defeats HTMLPurifier, and the admin user list renders the stored name without escaping — firing the payload in an administrator's session and enabling full platform admin takeover. CVSS 9.3 Critical. Found by Voke Cyber, fixed in 1.11.40.

More advisories are on the way as findings clear coordinated disclosure.  ·  Vulnerability Disclosure Policy

The same testing, on your software

The manual, by-hand testing that finds bugs like this is exactly what we do for clients across the Charlotte, NC area and nationwide.

Get a Quote