← Terug naar overzicht

CVE-2026-82872 affects ToolJet versions before v3.16.208, where the application fails to validate that the organizationId in API request paths matches the authenticated user's workspace. This flaw allows a workspace admin to perform unauthorized database table operations—including creating, viewing, and deleting tables—in other workspaces by manipulating the organizationId parameter in table-management API requests. The vulnerability is classified as an authorization bypass or Insecure Direct Object Reference (IDOR) issue. It poses a significant risk to multi-tenant ToolJet deployments where data isolation between workspaces is critical. The fix is included in ToolJet v3.16.208 and later. Organizations using older versions should upgrade immediately to prevent cross-workspace data exposure or manipulation.

Affected products

  • ToolJet before v3.16.208

Related CVE's

  • CVE-2026-82872

Categories

  • Database & Storage
  • Enterprise Applications
  • Identity & Access
  • Web Technologies