CVE-2026-107803
Received Received - Intake

SQL Injection in ProcessMaker Workflow Management Software

Vulnerability report for CVE-2026-107803, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

ProcessMaker is an open source workflow management software suite. Prior to 2026.14.3, the `GET /api/1.0/tasks` endpoint in ProcessMaker is vulnerable to SQL injection through the order_by parameter because `ProcessMaker\Traits\TaskControllerIndexMethods::applyColumnOrdering()` concatenates a user-controlled process_requests column name into a DB::raw() SQL subquery without validation or parameter binding. Any authenticated user can use blind, time-based queries to infer and extract data accessible to the ProcessMaker database account. This issue is fixed in version 2026.14.3.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ProcessMaker processmaker < 2026.14.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a SQL injection flaw in ProcessMaker's API endpoint GET /api/1.0/tasks. The order_by parameter allows authenticated users to inject malicious SQL queries by manipulating the column name without proper validation. The application directly concatenates user input into a raw SQL query, enabling attackers to extract data from the database through blind or time-based techniques.

Detection Guidance

To detect this vulnerability, monitor the /api/1.0/tasks endpoint for unusual SQL query patterns or time delays in responses. Test with payloads like order_by=process_requests.id AND SLEEP(5) to observe time-based delays. Check logs for raw SQL queries containing user-controlled input in the order_by parameter.

Impact Analysis

If you use ProcessMaker versions before 2026.14.3, an attacker with valid credentials could exploit this to read sensitive data from the database. This includes information accessible to the ProcessMaker database account, potentially exposing user data, workflow details, or other confidential information.

Compliance Impact

This vulnerability could lead to unauthorized data access, violating GDPR's data protection principles and HIPAA's security requirements for protected health information. Organizations using affected versions may face compliance violations, legal penalties, and reputational damage due to potential data breaches.

Mitigation Strategies

Upgrade ProcessMaker to version 2026.14.3 or later to address the SQL injection vulnerability in the GET /api/1.0/tasks endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107803. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart