Authorization Bypass in ToolJet Affects Data Security for Users
CVE-2026-82873
5.3MEDIUM
What is CVE-2026-82873?
ToolJet versions up to 3.0.0-ee-beta.2 are susceptible to significant authorization bypass vulnerabilities. These flaws allow authenticated users to access sensitive TooljetDB table schemas across different workspaces and potentially export application definitions that should be restricted due to granular permission settings. Specifically, attackers can manipulate the organization_id parameter in the POST /api/v2/resources/export API endpoint, breaching workspace boundaries and compromising the integrity of application access controls.
Affected Version(s)
ToolJet 0 <= 3.0.0-ee-beta.2
