HIGHVulnerability

CVE-2026-82871

ToolJet before v3.16.208 fails to validate organization membership in database read routes, allowing any authenticated user to access other organizations' table schemas and row data. Attackers can supply arbitrary organization IDs in URL parameters to list tables, retrieve column definitions, and execute join queries to read actual stored data from victim organizations.

Properties

severity
HIGH
score
7.7
epss_score
0.00218
cve_id
CVE-2026-82871
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
published_at
2026-08-31T09:17:08.017
last_modified
2026-09-02T16:17:27.127
epss_percentile
0.1221

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Missing Authorization

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-82871 — Ninja Signal Threat Intelligence | Ninja Signal