SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-85389

MEDIUM · CVSS 6.5 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Worklenz versions prior to 3.0.0 are vulnerable due to inadequate verification of task ownership, enabling authenticated users to access and retrieve sensitive task data from other tenants. This flaw allows attackers to exploit task-scoped API endpoints to obtain work logs, comments, attachments, and project insights belonging to different organizations. Organizations using affected versions should prioritize updating to mitigate potential data exposure risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85389
Severity
MEDIUM
CVSS
6.5
EPSS
0.26%

Original NVD Description

Worklenz before 3.0.0 fails to verify task ownership by organization when resolving task-scoped API endpoints, allowing authenticated users to access another tenant's task data. Attackers can query task endpoints with arbitrary task UUIDs to retrieve work logs, comments, attachments, and project insights belonging to other organizations.