PT-2026-83751 · Tooljet · Tooljet

·

CVE-2026-82874

·

Published

2026-08-31

·

Updated

2026-09-01

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ToolJet versions prior to 3.16.208
Description An issue exists where the software fails to validate if authenticated users belong to the organization specified in the organizationId path parameter of tooljet-db endpoints. This allows any user with Builder privileges to read, modify, and delete tables across tenant boundaries. Attackers can obtain victim organization IDs from public app endpoints and then use schema operation endpoints to disclose table schemas, create malicious tables, corrupt existing schemas, or permanently destroy data belonging to other organizations.
Recommendations Update ToolJet to version 3.16.208 or later.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82874

Affected Products

Tooljet