CVE-2026-107803 PUBLISHED

ProcessMaker has SQL injection in the tasks endpoint through the order_by parameter

Assigner: GitHub_M
Reserved: 08.10.2026 Published: 09.10.2026 Updated: 09.10.2026

ProcessMaker is an open source workflow management software suite. Prior to 2026.14.3, the GET /api/1.0/tasks endpoint in ProcessMaker is vulnerable to SQL injection through the order_by parameter because ProcessMaker\Traits\TaskControllerIndexMethods::applyColumnOrdering() concatenates a user-controlled process_requests column name into a DB::raw() SQL subquery without validation or parameter binding. Any authenticated user can use blind, time-based queries to infer and extract data accessible to the ProcessMaker database account. This issue is fixed in version 2026.14.3.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 6.5

Product Status

Vendor ProcessMaker
Product processmaker
Versions
  • Version < 2026.14.3 is affected

References

Problem Types

  • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CWE