CVE-2026-82873: ToolJet through 3.0.0-ee-beta.2 Cross-workspace Schema Disclosure via Export

Published Aug 31, 2026
·
Updated

ToolJet through 3.0.0-ee-beta.2 contains authorization bypass vulnerabilities in the POST /api/v2/resources/export endpoint that allow authenticated users to disclose TooljetDB table schemas across workspace boundaries and export app definitions across granular permission boundaries. Attackers can supply a body-provided organizationid parameter to access schemas from other workspaces, or bypass per-app authorization gates to export restricted app definitions within their workspace.

Affected Software

1 affected component
Tooljet tooljet<=3.0.0-ee-beta.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade ToolJet (TooljetDB) to a version that resolves this vulnerability.

    Fixed in 3.0.0-ee-beta.2
  2. Compensating control

    Mitigate by restricting access to the ToolJet POST /api/v2/resources/export endpoint so authenticated users cannot use it to export data across workspace boundaries or beyond granular permission gates.

Event History

Aug 31, 2026
CVE Published
via MITRE·08:46 AM
Data Sourced
via MITRE·08:46 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What level of access does an attacker need to exploit this issue?

The attacker must be an authenticated ToolJet user with low-level privileges. No user interaction is required, and the vulnerable endpoint is reachable over the network.

2

Who is exposed to cross-workspace schema disclosure?

Organizations using multiple ToolJet workspaces are exposed if an authenticated user can reach the export endpoint. An attacker can provide an organization_id in the request body to retrieve TooljetDB table schemas belonging to another workspace.

3

Can this affect restricted applications within the attacker's own workspace?

Yes. The export endpoint can bypass per-application authorization gates, allowing an authenticated user to export app definitions that are restricted by granular permissions within their workspace.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203