CVE-2026-82872: ToolJet before v3.16.208 Cross-Workspace Authorization Bypass
ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations. A workspace admin can create, view, and delete database tables in another workspace by replacing the organizationId parameter in table-management API requests.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated workspace administrator can exploit it. The attacker needs to modify the organizationId parameter in ToolJet DB table-management API requests to target another workspace.
Which operations can be performed against another workspace?
The affected table-management operations allow creating, viewing, and deleting ToolJet DB tables in another workspace.
Are installations on version 3.16.208 affected?
The issue affects ToolJet versions before 3.16.208. The provided information does not identify any affected configurations beyond the authorization behavior in those versions.