PT-2026-83746 · Unknown · Database Toolset

·

CVE-2026-82869

·

Published

2026-08-31

·

Updated

2026-08-31

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ToolJet Database versions prior to 3.16.44
Description A privilege escalation issue exists in the '/join tables' endpoint. The system fails to validate the role or workspace membership of authenticated users, granting them the JOIN TABLES ability. This allows an authenticated attacker to read arbitrary tables from any workspace by providing the target workspace identifiers in the request path while using their own valid credentials.
Recommendations Update ToolJet Database to version 3.16.44 or later. Restrict access to the '/join tables' endpoint as a temporary mitigation measure.

Fix

LPE

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82869

Affected Products

Database Toolset