Cross-Workspace Authorization Issue in ToolJet by ToolJet
CVE-2026-82872
7.1HIGH
What is CVE-2026-82872?
ToolJet before version 3.16.208 contains a vulnerability that allows a workspace admin to execute unauthorized database operations on other workspaces. Specifically, this occurs due to improper validation of the organizationId parameter in table-management API requests. As a result, an admin can create, view, and delete database tables outside their intended workspace, posing a significant security risk for affected installations.
Affected Version(s)
ToolJet 0 < 3.16.208
ToolJet 3.16.208
