CVE-2026-82872 PUBLISHED

ToolJet before v3.16.208 Cross-Workspace Authorization Bypass

Assigner: VulnCheck
Reserved: 31.08.2026 Published: 31.08.2026 Updated: 31.08.2026

ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations. A workspace admin can create, view, and delete database tables in another workspace by replacing the organizationId parameter in table-management API requests.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:H/AT:P/PR:H/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L
CVSS Score: 7.1

Product Status

Vendor ToolJet
Product ToolJet
Versions Default: unaffected
  • affected from 0 to 3.16.208 (excl.)
  • Version 3.16.208 is unaffected

Credits

  • owen050724 finder

References

Problem Types

  • Authorization Bypass Through User-Controlled Key CWE