CVE-2026-85389
Worklenz before 3.0.0 Authorization Bypass on Task-Scoped Endpoints
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
Worklenz before 3.0.0 fails to verify task ownership by organization when resolving task-scoped API endpoints, allowing authenticated users to access another tenant's task data. Attackers can query task endpoints with arbitrary task UUIDs to retrieve work logs, comments, attachments, and project insights belonging to other organizations.
| CWE | CWE-639 |
| Vendor | worklenz |
| Product | worklenz |
| Published | Sep 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for worklenz worklenz
Be the first to know when new medium vulnerabilities affecting worklenz worklenz are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
Worklenz / worklenz
0 < 3.0.0
References
github.com: https://github.com/Worklenz/worklenz/issues/396 github.com: https://github.com/Worklenz/worklenz github.com: https://github.com/Worklenz/worklenz/commit/f088ad0e36a23bb52857b46b3d4ce2533daeb65f github.com: https://github.com/Worklenz/worklenz/blob/v3.0.0/worklenz-backend/src/middlewares/verify-task-access.ts github.com: https://github.com/Worklenz/worklenz/releases/tag/v3.0.0 vulncheck.com: https://www.vulncheck.com/advisories/worklenz-before-3.0.0-authorization-bypass-on-task-scoped-endpoints
Credits
George Chen