LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-66416

Published
CVSS8.8
Severityhigh
WeaknessCWE-352
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perform state-changing actions on behalf of authenticated users by excluding the Laravel VerifyCsrfToken middleware from the global middleware stack in app/Http/Kernel.php. Attackers can craft malicious pages delivered via phishing emails or malicious websites to trigger unauthorized POST, PUT, and DELETE requests that create or delete projects, modify settings, and change permissions as any authenticated user.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-66416

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-66416.