← Terug naar overzicht

ToolJet versions before v3.16.208 contain a critical authorization flaw in database read routes that fails to validate organization membership. Any authenticated user can exploit this by supplying arbitrary organization IDs in URL parameters to access other organizations' data. The vulnerability allows attackers to list tables, retrieve column definitions, and execute join queries to read actual stored data from victim organizations. This represents a significant multi-tenant isolation failure in the ToolJet platform. The issue has been patched in v3.16.208 and is documented in both the GitHub Security Advisory GHSA-xqqj-pfc2-vf48 and VulnCheck advisories.

Affected products

  • ToolJet before v3.16.208

Related CVE's

  • CVE-2026-82871

Categories

  • Data Breach & Exfiltration
  • Database & Storage
  • Enterprise Applications
  • Identity & Access
  • Web Technologies