Cross-Tenant Confidentiality Breach in ToolJet by ToolJet
CVE-2026-55411

6.8MEDIUM

Key Information:

Vendor

Tooljet

Status
Vendor
CVE Published:
25 June 2026

What is CVE-2026-55411?

ToolJet, an open-source AI-native platform, has a vulnerability in its authenticated endpoint POST /api/data-sources/decrypt. Prior to version 3.20.1780-lts, this endpoint allows any authenticated user to decrypt data source credentials of other organizations by providing their credential_id. This significant issue arises because the endpoint lacks proper organization scoping and is not protected by necessary access controls. As a result, an attacker could exploit this to breach confidentiality across tenants, exposing sensitive data. The vulnerability has been resolved in version 3.20.1780-lts. Ensure your organization updates to this version to safeguard against potential exploits.

Affected Version(s)

ToolJet < 3.20.1780-lts

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.