CVE-2026-59713: Leantime
High severity, CVSS 8.1. EPSS: 0.2% chance of exploitation in the next 30 days.
Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without validating state parameters. Attackers can craft malicious callback URLs with attacker-controlled authorization codes to perform session fixation, logging victims in as the attacker.
Affected products
- Leantime Leantime: up to and including 3.4.4
Published 2026-07-06. Last modified 2026-09-17.