ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations. A workspace admin can create, view, and delete database tables in another workspace by replacing the organizationId parameter in table-management API requests.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 31 Aug 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations. A workspace admin can create, view, and delete database tables in another workspace by replacing the organizationId parameter in table-management API requests. | |
| Title | ToolJet before v3.16.208 Cross-Workspace Authorization Bypass | |
| First Time appeared |
Tooljet
Tooljet tooljet |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:tooljet:tooljet:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tooljet
Tooljet tooljet |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-08-31T08:46:40.926Z
Updated: 2026-09-01T15:07:06.516Z
Reserved: 2026-08-31T08:37:53.171Z
Link: CVE-2026-82872
Updated: 2026-09-01T15:06:57.355Z
Status : Deferred
Published: 2026-08-31T09:17:08.160
Modified: 2026-09-10T15:53:23.707
Link: CVE-2026-82872
No data.