CRITICALVulnerability

CVE-2026-82872

ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations. A workspace admin can create, view, and delete database tables in another workspace by replacing the organizationId parameter in table-management API requests.

Properties

severity
CRITICAL
score
9.1
epss_score
0.00258
cve_id
CVE-2026-82872
signal_observed_at
2026-09-15T21:12:48+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
published_at
2026-08-31T09:17:08.160
last_modified
2026-09-10T15:53:23.707
epss_percentile
0.17611

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Authorization Bypass Through User-Controlled Key

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-82872 — Ninja Signal Threat Intelligence | Ninja Signal