CVE-2026-82872 - ToolJet before v3.16.208 Cross-Workspace Authorization Bypass
CVE ID :CVE-2026-82872
Published : Aug. 31, 2026, 9:17 a.m. | 1 hour, 14 minutes ago
Description :ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations. A workspace admin can create, view, and delete database tables in another workspace by replacing the organizationId parameter in table-management API requests.
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 31, 2026, 9:17 a.m. | 1 hour, 14 minutes ago
Description :ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations. A workspace admin can create, view, and delete database tables in another workspace by replacing the organizationId parameter in table-management API requests.
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...