CVE-2026-85389 Details
Description
Worklenz before 3.0.0 fails to verify task ownership by organization when resolving task-scoped API endpoints, allowing authenticated users to access another tenant's task data. Attackers can query task endpoints with arbitrary task UUIDs to retrieve work logs, comments, attachments, and project insights belonging to other organizations.
A cross-tenant authorization bypass vulnerability has been identified in Worklenz versions prior to 3.0.0. This vulnerability allows authenticated users to access task data from other organizations through task-scoped API endpoints. The issue arises because the application fails to verify task ownership by organization, enabling users to query task endpoints with arbitrary task UUIDs and retrieve sensitive information such as work logs, comments, attachments, and project insights belonging to other organizations.
Users are advised to update to Worklenz version 3.0.0 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 3, 2026CISA-ADP
Assessed Sep 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Worklenz/worklenz | [email protected] | ProductVendor |
| https://github.com/Worklenz/worklenz/blob/v3.0.0/worklenz-backend/src/middlewares/verify-task-access.ts | [email protected] | Source CodeVendor |
| https://github.com/Worklenz/worklenz/commit/f088ad0e36a23bb52857b46b3d4ce2533daeb65f | [email protected] | Source CodeVendor |
| https://github.com/Worklenz/worklenz/issues/396 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/Worklenz/worklenz/releases/tag/v3.0.0 | [email protected] | Release NotesVendor |
| https://www.vulncheck.com/advisories/worklenz-before-3.0.0-authorization-bypass-on-task-scoped-endpoints | [email protected] | AdvisoryBundle |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Worklenz | >= 0, < 3.0.0 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 14, 2026 | CVE Modified | CISA-ADP |
| Sep 3, 2026 | New CVE Received | [email protected] |
Volerion