Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
2.4
CVE-2026-82874: ToolJet before 3.16.208 lets any logged‑in user edit other companies' data
CVE-2026-82874 · published 3 days ago
Summary
If you run ToolJet versions older than 3.16.208, a logged‑in Builder user can access data belonging to other organisations because the software does not check which company the user belongs to. This means an attacker could view, change or delete tables from another company's account, potentially corrupting or erasing important information. Upgrade to version 3.16.208 or later, or apply the vendor’s patch, to enforce proper access checks.
What to do
- Update tooljet tooljet to version 3.16.208 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| tooljet | tooljet | < 3.16.208 |
Original advisory text
ToolJet before v3.16.208 Cross-Tenant Authorization Bypass via tooljet-db
ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path parameter of tooljet-db endpoints, allowing any Builder user to read, modify, and delete tables across tenant boundaries. Attackers can extract victim organization IDs from public app endpoints, then exploit schema operation endpoints to disclose table schemas, plant malicious tables, corrupt existing schemas, or permanently destroy victim data without any relationship to the target organization.
Severity
2.4
Low
CVSS 3.1: 9.9 (NVD)
CVSS 4.0: 2.4 (NVD)
Exploitation
EPSS <1%
Type
CWE-639Authorization Bypass Through User-Controlled Key
Timeline
Published31 Aug 2026
Updated2 Sep 2026
First seen31 Aug 2026
Monitor software like this
Free during beta