CVE-2026-85389
Received Received - Intake

Worklenz Unauthorized Task Data Access Before 3.0.0

Vulnerability report for CVE-2026-85389, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-03

Last updated on: 2026-09-03

Assigner: VulnCheck

Description

Worklenz before 3.0.0 fails to verify task ownership by organization when resolving task-scoped API endpoints, allowing authenticated users to access another tenant's task data. Attackers can query task endpoints with arbitrary task UUIDs to retrieve work logs, comments, attachments, and project insights belonging to other organizations.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-03
Last Modified
2026-09-03
Generated
2026-09-04
AI Q&A
2026-09-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
worklenz worklenz to 3.0.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Worklenz before version 3.0.0 has a flaw where it does not properly check if a user belongs to the same organization when accessing task-specific API endpoints. This allows authenticated users to view or manipulate task data belonging to other organizations by simply providing arbitrary task IDs.

Detection Guidance

To detect this vulnerability, monitor API endpoint access logs for unauthorized queries to task-scoped endpoints with arbitrary task UUIDs. Check for repeated requests to endpoints like /tasks/{task_id}/logs, /tasks/{task_id}/comments, or /tasks/{task_id}/attachments from non-admin users.

Impact Analysis

If you use Worklenz before 3.0.0, an attacker with valid credentials could access sensitive task data such as work logs, comments, attachments, and project insights from other organizations. This could lead to data leaks, unauthorized access to confidential information, or potential misuse of organizational resources.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR's data protection principles and HIPAA's requirements for safeguarding protected health information. Organizations using affected versions may face compliance violations, legal penalties, and reputational damage.

Mitigation Strategies

Immediately upgrade Worklenz to version 3.0.0 or later. Review and restrict API endpoint access controls to enforce strict tenant and task ownership verification. Audit logs for any unauthorized data access and revoke suspicious user sessions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85389. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart