Authorization Flaw in ToolJet's Database API Exposes User Data
CVE-2026-73068

5.9MEDIUM

Key Information:

Vendor

Tooljet

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-73068?

The ToolJet Database HTTP API prior to version 3.20.207 contains an authorization flaw affecting users accessing organization-specific data. The API fails to verify if the user requesting operations belongs to the specified organization, allowing authenticated users to manipulate data across different workspaces. This includes unauthorized retrieval of sensitive table information and the capability to alter tables without appropriate permissions. System administrators are advised to upgrade to version 3.20.207-lts to mitigate risks associated with this vulnerability.

Affected Version(s)

ToolJet 3.20.207-lts

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.