Description
ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations. A workspace admin can create, view, and delete database tables in another workspace by replacing the organizationId parameter in table-management API requests.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Mon, 31 Aug 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations. A workspace admin can create, view, and delete database tables in another workspace by replacing the organizationId parameter in table-management API requests. | |
| Title | ToolJet before v3.16.208 Cross-Workspace Authorization Bypass | |
| First Time appeared |
Tooljet
Tooljet tooljet |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:tooljet:tooljet:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tooljet
Tooljet tooljet |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-31T08:46:40.926Z
Reserved: 2026-08-31T08:37:53.171Z
Link: CVE-2026-82872
No data.
Status : Received
Published: 2026-08-31T09:17:08.160
Modified: 2026-08-31T09:17:08.160
Link: CVE-2026-82872
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-639
Authorization Bypass Through User-Controlled Key