CVE-2026-59712
Leantime's Users::getUser method in the JSON-RPC API lacks proper authorization checks, allowing authenticated users to retrieve full user c
CVSS
8.1
High
EPSS
0.3%
p16
KEV
—
Exploit Today
5
0-100
Published: Jul 6, 2026 · Last modified: Jul 7, 2026 · CWE-639
0.3%EPSS · 30 days0.3%
2026-07-072026-07-20
Leantime's Users::getUser method in the JSON-RPC API lacks proper authorization checks, allowing authenticated users to retrieve full user credential rows including password hashes, TOTP secrets, and session tokens. Attackers can exploit this by calling users.getUser with arbitrary user IDs to enumerate all accounts and obtain credentials for offline password cracking, 2FA bypass, and session hijacking.
- github.comhttps://github.com/Leantime/leantime
- github.comhttps://github.com/Leantime/leantime/commit/4f2612d13e0e8a2093092a846b44506cf133b671
- github.comhttps://github.com/Leantime/leantime/issues/3556
- www.vulncheck.comhttps://www.vulncheck.com/advisories/leantime-credential-disclosure-via-unauthenticated-json-rpc-users-getuser-method
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-552558.4 HIG42.9%
KEV—63Langflow Authorization Bypass Through User-Controlled Key Vulnerability12dCVE-2021-464168.1 HIG89.9%
——27Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.7dCVE-2022-289867.5 HIG80.9%
——24LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object references (IDOR) vulnerability, which allows remote attackers to update sensitive records such as email, password and phone number of other user accounts.12dCVE-2020-234465.3 MED65.5%
——20Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API12dCVE-2021-33806.5 MED61.6%
——18Insecure direct object reference (IDOR) vulnerability in ICREM H8 SSRMS allows attackers to disclose sensitive information via the Print Invoice Functionality.12dCVE-2022-362029.8 CRI51.6%
——15Doctor's Appointment System1.0 is vulnerable to Incorrect Access Control via edoc/patient/settings.php. The settings.php is affected by Broken Access Control (IDOR) via id= parameter.12d