Description
ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any builder-role user to create, alter, or drop tables in other organizations' databases. Attackers can exploit missing organization-resolving guards to permanently delete tables, insert arbitrary data, and modify schemas across tenant boundaries on shared instances.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Mon, 31 Aug 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any builder-role user to create, alter, or drop tables in other organizations' databases. Attackers can exploit missing organization-resolving guards to permanently delete tables, insert arbitrary data, and modify schemas across tenant boundaries on shared instances. | |
| Title | ToolJet before v3.16.208 Cross-Tenant Database Manipulation | |
| First Time appeared |
Tooljet
Tooljet tooljet |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:tooljet:tooljet:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tooljet
Tooljet tooljet |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-31T08:46:39.571Z
Reserved: 2026-08-31T08:37:53.170Z
Link: CVE-2026-82870
No data.
Status : Received
Published: 2026-08-31T09:17:07.863
Modified: 2026-08-31T09:17:07.863
Link: CVE-2026-82870
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-639
Authorization Bypass Through User-Controlled Key