CVE-2026-82872
CRITICAL
NVD
CVSS Score
9.1
Severity
CRITICAL
Published
Aug 31, 2026
Vendor
unknown
Description
ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations. A workspace admin can create, view, and delete database tables in another workspace by replacing the organizationId parameter in table-management API requests.