CVE-2026-85388: Worklenz through 3.0.0 SQL Injection via the sort-field Query Parameter

Published Sep 3, 2026
·
Updated

Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY clauses. Attackers can use time-based and boolean-based blind SQL injection techniques to extract sensitive database content including password hashes from other tenants. This is an incomplete fix for CVE-2026-25947.

Affected Software

1 affected component
Worklenz<=3.0.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Worklenz to a version that resolves this vulnerability.

    Fixed in 3.0.0
  2. Compensating control

    Restrict access to the Worklenz pagination/sort functionality (e.g., limit who can reach endpoints that use the sort-field query parameter) so authenticated users cannot exploit ORDER BY expression injection to extract cross-tenant data.

Event History

Sep 3, 2026
CVE Published
via MITRE·06:54 PM
Data Sourced
via MITRE·06:54 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What level of access does an attacker need to exploit this issue?

An attacker needs an authenticated Worklenz account with permission to reach an endpoint that uses the affected pagination helper functions. No user interaction is required.

2

What data could be exposed?

The injection can be used to run arbitrary PostgreSQL expressions in ORDER BY clauses and extract database content through blind techniques. The reported impact includes sensitive data such as password hashes belonging to other tenants.

3

Is this related to an earlier vulnerability?

Yes. It is described as an incomplete fix for CVE-2026-25947, so environments that applied only that earlier fix may still be affected through the sort-field parameter.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203