CVE-2026-82874: ToolJet before v3.16.208 Cross-Tenant Authorization Bypass via tooljet-db
ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path parameter of tooljet-db endpoints, allowing any Builder user to read, modify, and delete tables across tenant boundaries. Attackers can extract victim organization IDs from public app endpoints, then exploit schema operation endpoints to disclose table schemas, plant malicious tables, corrupt existing schemas, or permanently destroy victim data without any relationship to the target organization.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated ToolJet user with the Builder role can exploit it. The attacker does not need any membership or other relationship with the targeted organization.
What does an attacker need to target another organization?
The attacker needs a valid authenticated Builder account and a victim organization ID. Victim organization IDs can be obtained from public app endpoints.
Are cross-tenant data changes possible, or is this limited to reading data?
This issue permits reading, modifying, and deleting tables across tenant boundaries through tooljet-db schema operation endpoints. An attacker can disclose schemas, create malicious tables, corrupt existing schemas, or permanently destroy victim data.
Which versions require remediation?
ToolJet versions before 3.16.208 are affected. Upgrading to version 3.16.208 or later addresses the affected version range described here.