Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-92772— Leantime before 3.9.6 Unauthorized Plugin Installation via HTMX

Quick assessment

Affected
Leantime leantime
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Leantime 3.9.6 之前的版本中存在一个授权绕过漏洞:HTMX 插件安装端点缺少权限验证。具有有限角色的已认证用户可以安装市场插件,并能控制包括标识符(identifier)、版本(version)和许可证密钥(license key)等任意属性,从而部署恶意插件。

CVSS 7.1 · High EPSS 0.53% · P43

Affected Version Matrix 1

VendorProduct Version RangeStatus
Leantime leantime < 3.9.6 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-92772

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Leantime before 3.9.6 Unauthorized Plugin Installation via HTMX
Source: CVE Program / CVE List V5
Vulnerability Description
Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks permission validation. Authenticated users with limited roles can install marketplace plugins and control arbitrary properties including identifier, version, and license key to deploy malicious plugins.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Leantime leantime 0 ~ 3.9.6 -

II. Public POCs for CVE-2026-92772

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-92772

请登录查看更多情报信息。

Other References for CVE-2026-92772 (5)

IV. Related Vulnerabilities

V. Comments for CVE-2026-92772

No comments yet


Leave a comment