ToolJet v3.16.208 之前版本中存在一个授权绕过漏洞:TooljetDB 控制器端点从 URL 路径中接收 ,但未验证该值是否与当前认证用户所属的工作区(workspace)一致。已认证用户可以通过在请求中操控 参数,从而在其他工作区中枚举、创建、重命名和删除 TooljetDB 数据表。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82874 | 9.9 CRITICAL | ToolJet before v3.16.208 Cross-Tenant Authorization Bypass via tooljet-db |
| CVE-2026-82870 | 9.6 CRITICAL | ToolJet before v3.16.208 Cross-Tenant Database Manipulation |
| CVE-2026-82872 | 9.1 CRITICAL | ToolJet before v3.16.208 Cross-Workspace Authorization Bypass |
| CVE-2026-82869 | 7.7 HIGH | ToolJet Database before v3.16.44 Privilege Escalation via join_tables |
| CVE-2026-82871 | 7.7 HIGH | ToolJet before v3.16.208 Cross-Organization Data Read via Database Routes |
| CVE-2026-82873 | 5.0 MEDIUM | ToolJet through 3.0.0-ee-beta.2 Cross-workspace Schema Disclosure via Export |
No comments yet