A vulnerability was found in Leantime up to 3.6.2 and classified as problematic. This affects the function
tickets.getMilestone of the component Tickets Milestone API. Executing a manipulation of the argument milestone_id can lead to improper access controls.
This vulnerability is registered as CVE-2026-66412. It is possible to launch the attack remotely. No exploit is available.