PT-2026-85222 · Worklenz · Worklenz

·

CVE-2026-85389

·

Published

2026-09-03

·

Updated

2026-09-03

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Worklenz versions prior to 3.0.0
Description An authorization bypass exists when resolving task-scoped API endpoints because the system fails to verify task ownership by organization. This allows authenticated users to access task data belonging to other tenants. By querying task endpoints with arbitrary task UUIDs, an attacker can retrieve project insights, attachments, comments, and work logs from other organizations.
Recommendations Update to version 3.0.0 or later.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85389

Affected Products

Worklenz