CVE-2026-82875

ToolJet before v3.16.208 contains an authorization bypass vulnerability in TooljetDB controller endpoints that accept organizationId from URL path without verifying it matches the authenticated user's workspace. Authenticated users can enumerate, create, rename, and delete TooljetDB tables in any other workspace by manipulating the organizationId parameter in requests.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-31 09:17

Updated : 2026-08-31 20:56


NVD link : CVE-2026-82875

Mitre link : CVE-2026-82875

CVE.ORG link : CVE-2026-82875


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization