PT-2026-85222 · Worklenz · Worklenz
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Worklenz versions prior to 3.0.0
Description
An authorization bypass exists when resolving task-scoped API endpoints because the system fails to verify task ownership by organization. This allows authenticated users to access task data belonging to other tenants. By querying task endpoints with arbitrary task UUIDs, an attacker can retrieve project insights, attachments, comments, and work logs from other organizations.
Recommendations
Update to version 3.0.0 or later.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Worklenz