Cross-Tenant Database Manipulation in ToolJet by ToolJet
CVE-2026-82870

7HIGH

Key Information:

Vendor

Tooljet

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-82870?

ToolJet versions prior to v3.16.208 expose serious security weaknesses due to inadequate validation of organizationId ownership within their database interaction routes. This flaw enables users with builder roles to manipulate databases across organizational boundaries. Malicious actors can exploit this oversight to delete critical tables, insert unauthorized data, and alter database schemas. The absence of organization-resolving guards raises significant risks in shared environments, potentially leading to data breaches and loss of data integrity across multiple tenants.

Affected Version(s)

ToolJet 0 < 3.16.208

ToolJet 3.16.208

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

komyunghan
.