CVE-2026-82872 affects ToolJet versions before v3.16.208, where the application fails to validate that the organizationId in API request paths matches the authenticated user's workspace. This flaw allows a workspace admin to perform unauthorized database table operations—including creating, viewing, and deleting tables—in other workspaces by manipulating the organizationId parameter in table-management API requests. The vulnerability is classified as an authorization bypass or Insecure Direct Object Reference (IDOR) issue. It poses a significant risk to multi-tenant ToolJet deployments where data isolation between workspaces is critical. The fix is included in ToolJet v3.16.208 and later. Organizations using older versions should upgrade immediately to prevent cross-workspace data exposure or manipulation.