MEDIUMVulnerability

CVE-2026-82875

ToolJet before v3.16.208 contains an authorization bypass vulnerability in TooljetDB controller endpoints that accept organizationId from URL path without verifying it matches the authenticated user's workspace. Authenticated users can enumerate, create, rename, and delete TooljetDB tables in any other workspace by manipulating the organizationId parameter in requests.

Properties

severity
MEDIUM
score
5.5
cve_id
CVE-2026-82875
signal_observed_at
2026-09-17T21:31:49+00:00
vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
published_at
2026-08-31T09:17:08.610
last_modified
2026-09-17T18:17:10.377

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Incorrect Authorization

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-82875 — Ninja Signal Threat Intelligence | Ninja Signal