Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-82874— ToolJet before v3.16.208 Cross-Tenant Authorization Bypass via tooljet-db

Quick assessment

Affected
ToolJet ToolJet
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 v3.16.208 之前,ToolJet 未能验证经过身份验证的用户是否确实属于 端点中 路径参数所指定的组织。这一缺陷允许任何拥有 Builder 权限的用户跨租户边界读取、修改和删除表。攻击者可以通过公开的 App 端点提取受害组织的 ID,随后利用模式操作端点来:披露表结构、植入恶意表、损坏现有结构,或在与目标组织无任何关联的情况下永久销毁受害者的数据。

CVSS 9.9 · Critical EPSS 0.26% · P17

Affected Version Matrix 2

VendorProduct Version RangeStatus
ToolJet ToolJet < 3.16.208 affected
3.16.208 unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-82874

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ToolJet before v3.16.208 Cross-Tenant Authorization Bypass via tooljet-db
Source: CVE Program / CVE List V5
Vulnerability Description
ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path parameter of tooljet-db endpoints, allowing any Builder user to read, modify, and delete tables across tenant boundaries. Attackers can extract victim organization IDs from public app endpoints, then exploit schema operation endpoints to disclose table schemas, plant malicious tables, corrupt existing schemas, or permanently destroy victim data without any relationship to the target organization.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ToolJet ToolJet 0 ~ 3.16.208 -

II. Public POCs for CVE-2026-82874

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-82874

登录查看更多情报信息。

Other References for CVE-2026-82874 (2)

Same Patch Batch · ToolJet · 2026-08-31 · 7 CVEs total

CVE-2026-82870 9.6 CRITICAL ToolJet before v3.16.208 Cross-Tenant Database Manipulation
CVE-2026-82872 9.1 CRITICAL ToolJet before v3.16.208 Cross-Workspace Authorization Bypass
CVE-2026-82869 7.7 HIGH ToolJet Database before v3.16.44 Privilege Escalation via join_tables
CVE-2026-82871 7.7 HIGH ToolJet before v3.16.208 Cross-Organization Data Read via Database Routes
CVE-2026-82875 5.5 MEDIUM ToolJet before v3.16.208 Authorization Bypass via organizationId
CVE-2026-82873 5.0 MEDIUM ToolJet through 3.0.0-ee-beta.2 Cross-workspace Schema Disclosure via Export

IV. Related Vulnerabilities

V. Comments for CVE-2026-82874

No comments yet


Leave a comment