PT-2026-83748 · Tooljet · Tooljet

·

CVE-2026-82871

·

Published

2026-08-31

·

Updated

2026-09-02

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ToolJet versions prior to 3.16.208
Description An issue exists where organization membership is not validated in database read routes. This allows any authenticated user to access table schemas and row data belonging to other organizations. An attacker can provide arbitrary organization IDs in URL parameters to list tables, retrieve column definitions, and execute join queries to read stored data from victim organizations.
Recommendations Update ToolJet to version 3.16.208 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82871

Affected Products

Tooljet