Description
ToolJet through 3.0.0-ee-beta.2 contains authorization bypass vulnerabilities in the POST /api/v2/resources/export endpoint that allow authenticated users to disclose TooljetDB table schemas across workspace boundaries and export app definitions across granular permission boundaries. Attackers can supply a body-provided organization_id parameter to access schemas from other workspaces, or bypass per-app authorization gates to export restricted app definitions within their workspace.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Mon, 31 Aug 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ToolJet through 3.0.0-ee-beta.2 contains authorization bypass vulnerabilities in the POST /api/v2/resources/export endpoint that allow authenticated users to disclose TooljetDB table schemas across workspace boundaries and export app definitions across granular permission boundaries. Attackers can supply a body-provided organization_id parameter to access schemas from other workspaces, or bypass per-app authorization gates to export restricted app definitions within their workspace. | |
| Title | ToolJet through 3.0.0-ee-beta.2 Cross-workspace Schema Disclosure via Export | |
| First Time appeared |
Tooljet
Tooljet tooljet |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:tooljet:tooljet:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tooljet
Tooljet tooljet |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-31T08:46:41.702Z
Reserved: 2026-08-31T08:38:43.268Z
Link: CVE-2026-82873
No data.
Status : Received
Published: 2026-08-31T09:17:08.310
Modified: 2026-08-31T09:17:08.310
Link: CVE-2026-82873
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-639
Authorization Bypass Through User-Controlled Key