Cross-Tenant Confidentiality Breach in ToolJet by ToolJet
CVE-2026-55411
6.8MEDIUM
What is CVE-2026-55411?
ToolJet, an open-source AI-native platform, has a vulnerability in its authenticated endpoint POST /api/data-sources/decrypt. Prior to version 3.20.1780-lts, this endpoint allows any authenticated user to decrypt data source credentials of other organizations by providing their credential_id. This significant issue arises because the endpoint lacks proper organization scoping and is not protected by necessary access controls. As a result, an attacker could exploit this to breach confidentiality across tenants, exposing sensitive data. The vulnerability has been resolved in version 3.20.1780-lts. Ensure your organization updates to this version to safeguard against potential exploits.
Affected Version(s)
ToolJet < 3.20.1780-lts
