PT-2026-83749 · Tooljet · Tooljet
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ToolJet versions prior to 3.16.208
Description
Insufficient validation occurs when checking if the path
organizationId matches the authenticated user's workspace during ToolJet DB table operations. This allows a workspace administrator to create, view, and delete database tables in a different workspace by modifying the organizationId parameter in table-management API requests.Recommendations
Update to version 3.16.208 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tooljet