---
id: CVE-2026-92772
title: >-
  Leantime before 3.9.6 contains an authorization bypass vulnerability in the
  HTMX plugin install endpoint that lacks permission validation
summary: >-
  Leantime before 3.9.6 contains an authorization bypass vulnerability in the
  HTMX plugin install endpoint that lacks permission validation. Authenticated
  users with limited roles can install marketplace plugins and control arbitrary
  prope…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'
cwe:
  - CWE-862
vendor: Leantime
product: leantime
affected:
  - leantime < 3.9.6
published: '2026-09-16'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T15:16:59.167'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92772'
references:
  - url: 'https://github.com/Leantime/leantime'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Leantime/leantime/blob/v3.9.5/app/Domain/Plugins/Controllers/Marketplace.php#L24
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Leantime/leantime/blob/v3.9.5/app/Domain/Plugins/Hxcontrollers/Details.php#L25-L40
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Leantime/leantime/blob/v3.9.5/app/Domain/Plugins/Services/Plugins.php#L546-L561
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Leantime/leantime/blob/v3.9.6/app/Domain/Plugins/Hxcontrollers/Details.php#L27
    label: disclosure@vulncheck.com
  - url: 'https://github.com/Leantime/leantime/issues/3757'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/leantime-before-3.9.6-unauthorized-plugin-installation-via-htmx
    label: disclosure@vulncheck.com
  - url: 'https://github.com/Leantime/leantime/issues/3757'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T14:51:54.092037Z'
ingestedAt: '2026-09-16T21:05:36.892Z'
epss: 0.00528
epssPercentile: 0.42223
---

## Overview

Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks permission validation. Authenticated users with limited roles can install marketplace plugins and control arbitrary properties including identifier, version, and license key to deploy malicious plugins.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
