CVE-2026-82871 PUBLISHED

ToolJet before v3.16.208 Cross-Organization Data Read via Database Routes

Assigner: VulnCheck
Reserved: 31.08.2026 Published: 31.08.2026 Updated: 31.08.2026

ToolJet before v3.16.208 fails to validate organization membership in database read routes, allowing any authenticated user to access other organizations' table schemas and row data. Attackers can supply arbitrary organization IDs in URL parameters to list tables, retrieve column definitions, and execute join queries to read actual stored data from victim organizations.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
CVSS Score: 8.2

Product Status

Vendor ToolJet
Product ToolJet
Versions Default: unaffected
  • affected from 0 to 3.16.208 (excl.)
  • Version 3.16.208 is unaffected

Credits

  • komyunghan reporter

References

Problem Types

  • Missing Authorization CWE