PT-2026-83752 · Tooljet · Tooljet
CVSS v3.1
5.5
Medium
| Vector | AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
ToolJet versions prior to 3.16.208
Description
An authorization bypass exists in TooljetDB controller endpoints that accept
organizationId from the URL path without verifying if it matches the authenticated user's workspace. This allows authenticated users to enumerate, create, rename, and delete TooljetDB tables in any other workspace by manipulating the organizationId parameter.Recommendations
Update ToolJet to version 3.16.208 or later.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tooljet