CVE-2026-82870
Received Received - Intake

ToolJet Database Schema Manipulation via Missing Organization Validation

Vulnerability report for CVE-2026-82870, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-31

Last updated on: 2026-08-31

Assigner: VulnCheck

Description

ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any builder-role user to create, alter, or drop tables in other organizations' databases. Attackers can exploit missing organization-resolving guards to permanently delete tables, insert arbitrary data, and modify schemas across tenant boundaries on shared instances.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-31
Last Modified
2026-08-31
Generated
2026-08-31
AI Q&A
2026-08-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tooljet tooljet to 3.16.208 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes. This allows any authenticated user with the builder role to perform unauthorized actions on other organizations' databases, such as creating, altering, or dropping tables, inserting arbitrary data, or modifying schemas across tenant boundaries.

Detection Guidance

Check ToolJet logs for unauthorized database operations or cross-organization actions. Look for requests with mismatched organizationId parameters in database write/destroy routes. Verify if builder-role users can access or modify data outside their organization.

Impact Analysis

Attackers can exploit this to permanently delete tables, insert malicious data, or alter database schemas in other organizations. This could lead to data loss, corruption, or unauthorized access to sensitive information across shared instances.

Compliance Impact

This vulnerability could lead to unauthorized data access or destruction, violating compliance requirements for data integrity and confidentiality in standards like GDPR and HIPAA. Organizations may face legal penalties or reputational damage due to breaches.

Mitigation Strategies

Upgrade ToolJet to version 3.16.208 or later to apply the patch. Review and restrict builder-role permissions to prevent unauthorized database access. Monitor database activity for suspicious cross-organization changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82870. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart