SQL Injection in Worklenz Limits Data Security for Users
CVE-2026-85388

8.6HIGH

Key Information:

Vendor

Worklenz

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-85388?

Worklenz, up to version 3.0.0, suffers from an inadequate validation of the sort-field query parameter in its pagination helper functions. This oversight enables authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY clauses. Consequently, attackers may exploit this flaw using time-based and boolean-based blind SQL injection techniques to extract sensitive information, including password hashes, from the databases of other tenants. This vulnerability appears to be an incomplete resolution of the earlier CVE-2026-25947.

Affected Version(s)

worklenz 0 <= 3.0.0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.