top of page
perceptive_background_267k.jpg

ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations…

Published:

31 augustus 2026 om 00:00:00

Alert date:

31 augustus 2026 om 12:05:42

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Identity & Access, Database & Storage, Web Technologies

CVE-2026-82872 affects ToolJet versions before v3.16.208, where the application fails to validate that the organizationId in API request paths matches the authenticated user's workspace. This flaw allows a workspace admin to perform unauthorized database table operations—including creating, viewing, and deleting tables—in other workspaces by manipulating the organizationId parameter in table-management API requests. The vulnerability is classified as an authorization bypass or Insecure Direct Object Reference (IDOR) issue. It poses a significant risk to multi-tenant ToolJet deployments where data isolation between workspaces is critical. The fix is included in ToolJet v3.16.208 and later. Organizations using older versions should upgrade immediately to prevent cross-workspace data exposure or manipulation.

Technical details

Mitigation steps:

Affected products:

ToolJet before v3.16.208

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page