← Back to overview

ToolJet Database versions before v3.16.44 contain a critical privilege escalation vulnerability in the join_tables endpoint. The flaw grants JOIN_TABLES ability to all authenticated users without performing role or workspace membership validation. This allows attackers to read arbitrary database tables belonging to any workspace by supplying victim workspace identifiers in the request path. The attacker only needs to authenticate with their own valid workspace credentials to exploit this. The vulnerability enables unauthorized cross-workspace data access, posing significant data confidentiality risks. A fix is available in ToolJet Database v3.16.44 and later. The issue is tracked as CVE-2026-82869 and has been disclosed via GitHub Security Advisories and VulnCheck.

Affected products

  • ToolJet Database (versions before v3.16.44)

Related CVE's

  • CVE-2026-82869

Categories

  • Database & Storage
  • Enterprise Applications
  • Identity & Access
  • Web Technologies