CVE-2026-107803: ProcessMaker has SQL injection in the tasks endpoint through the order_by parameter
ProcessMaker is an open source workflow management software suite. Prior to 2026.14.3, the GET /api/1.0/tasks endpoint in ProcessMaker is vulnerable to SQL injection through the orderby parameter because ProcessMaker\Traits\TaskControllerIndexMethods::applyColumnOrdering() concatenates a user-controlled processrequests column name into a DB::raw() SQL subquery without validation or parameter binding. Any authenticated user can use blind, time-based queries to infer and extract data accessible to the ProcessMaker database account. This issue is fixed in version 2026.14.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ProcessMakerto a version that resolves this vulnerability.Fixed in 2026.14.3