{"id":"CVE-2026-107803","title":"ProcessMaker is an open source workflow management software suite","summary":"ProcessMaker is an open source workflow management software suite. Prior to 2026.14.3, the `GET /api/1.0/tasks` endpoint in ProcessMaker is vulnerable to SQL injection through the order_by parameter because `ProcessMaker\\Traits\\TaskContr…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-89"],"published":"2026-10-09","updated":"2026-10-09","sourceUpdated":"2026-10-09T18:17:02.487","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107803","references":[{"url":"https://github.com/ProcessMaker/processmaker/commit/2622b7ae810e02c47157028331c45470567e7b79","label":"security-advisories@github.com"},{"url":"https://github.com/ProcessMaker/processmaker/pull/9041","label":"security-advisories@github.com"},{"url":"https://github.com/ProcessMaker/processmaker/releases/tag/v2026.14.3","label":"security-advisories@github.com"},{"url":"https://github.com/ProcessMaker/processmaker/security/advisories/GHSA-xf7p-gp7c-w7gh","label":"security-advisories@github.com"}],"tags":["nvd"],"ingestedAt":"2026-10-09T15:00:31.365Z","slug":"CVE-2026-107803","body":"## Overview\n\nProcessMaker is an open source workflow management software suite. Prior to 2026.14.3, the `GET /api/1.0/tasks` endpoint in ProcessMaker is vulnerable to SQL injection through the order_by parameter because `ProcessMaker\\Traits\\TaskControllerIndexMethods::applyColumnOrdering()` concatenates a user-controlled process_requests column name into a DB::raw() SQL subquery without validation or parameter binding. Any authenticated user can use blind, time-based queries to infer and extract data accessible to the ProcessMaker database account. This issue is fixed in version 2026.14.3.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}