CVE-2026-82873

ToolJet through 3.0.0-ee-beta.2 contains authorization bypass vulnerabilities in the POST /api/v2/resources/export endpoint that allow authenticated users to disclose TooljetDB table schemas across workspace boundaries and export app definitions across granular permission boundaries. Attackers can supply a body-provided organization_id parameter to access schemas from other workspaces, or bypass per-app authorization gates to export restricted app definitions within their workspace.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-31 09:17

Updated : 2026-09-10 15:53


NVD link : CVE-2026-82873

Mitre link : CVE-2026-82873

CVE.ORG link : CVE-2026-82873


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key