CVE-2026-82872
EUVD-2026-6840731.08.2026, 09:17
ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations. A workspace admin can create, view, and delete database tables in another workspace by replacing the organizationId parameter in table-management API requests.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| tooljet | tooljet | 𝑥 < 3.16.208 | CNA |
Common Weakness Enumeration