Authorization Bypass Vulnerability in ToolJet by ToolJet
CVE-2026-82875

5.1MEDIUM

Key Information:

Vendor

Tooljet

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-82875?

ToolJet prior to version 3.16.208 is susceptible to an authorization bypass vulnerability found within the TooljetDB controller endpoints. This issue stems from the software's failure to properly validate the organizationId parameter extracted from the URL path, allowing authenticated users to access and manipulate databases across different workspaces. By altering the organizationId in their requests, users could enumerate, create, rename, or delete TooljetDB tables within other users' workspaces, compromising data integrity and security.

Affected Version(s)

ToolJet 0 < 3.16.208

ToolJet 3.16.208

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

JohannesLks
.