Authorization Bypass in ToolJet Affects Data Security for Users
CVE-2026-82873

5.3MEDIUM

Key Information:

Vendor

Tooljet

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-82873?

ToolJet versions up to 3.0.0-ee-beta.2 are susceptible to significant authorization bypass vulnerabilities. These flaws allow authenticated users to access sensitive TooljetDB table schemas across different workspaces and potentially export application definitions that should be restricted due to granular permission settings. Specifically, attackers can manipulate the organization_id parameter in the POST /api/v2/resources/export API endpoint, breaching workspace boundaries and compromising the integrity of application access controls.

Affected Version(s)

ToolJet 0 <= 3.0.0-ee-beta.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.