


Perceptive Security
SOC/SIEM Consultancy

ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations…
Published:
31 augustus 2026 om 00:00:00
Alert date:
31 augustus 2026 om 12:05:42
Source:
nvd.nist.gov
Enterprise Applications, Identity & Access, Database & Storage, Web Technologies
CVE-2026-82872 affects ToolJet versions before v3.16.208, where the application fails to validate that the organizationId in API request paths matches the authenticated user's workspace. This flaw allows a workspace admin to perform unauthorized database table operations—including creating, viewing, and deleting tables—in other workspaces by manipulating the organizationId parameter in table-management API requests. The vulnerability is classified as an authorization bypass or Insecure Direct Object Reference (IDOR) issue. It poses a significant risk to multi-tenant ToolJet deployments where data isolation between workspaces is critical. The fix is included in ToolJet v3.16.208 and later. Organizations using older versions should upgrade immediately to prevent cross-workspace data exposure or manipulation.
Technical details
Mitigation steps:
Affected products:
ToolJet before v3.16.208
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-82872
https://github.com/ToolJet/ToolJet/security/advisories/GHSA-2jhv-482p-4php
https://www.vulncheck.com/advisories/tooljet-before-3.16.208-cross-workspace-authorization-bypass
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
