CVE-2026-82875
- EPSS 0.14%
- Veröffentlicht 31.08.2026 08:46:43
- Zuletzt bearbeitet 17.09.2026 18:17:10
ToolJet before v3.16.208 contains an authorization bypass vulnerability in TooljetDB controller endpoints that accept organizationId from URL path without verifying it matches the authenticated user's workspace. Authenticated users can enumerate, cre...
CVE-2026-82874
- EPSS 0.26%
- Veröffentlicht 31.08.2026 08:46:42
- Zuletzt bearbeitet 17.09.2026 19:17:04
ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path parameter of tooljet-db endpoints, allowing any Builder user to read, modify, and delete tables across tenant boundari...
CVE-2026-82873
- EPSS 0.18%
- Veröffentlicht 31.08.2026 08:46:41
- Zuletzt bearbeitet 10.09.2026 15:53:23
ToolJet through 3.0.0-ee-beta.2 contains authorization bypass vulnerabilities in the POST /api/v2/resources/export endpoint that allow authenticated users to disclose TooljetDB table schemas across workspace boundaries and export app definitions acro...
CVE-2026-82872
- EPSS 0.26%
- Veröffentlicht 31.08.2026 08:46:40
- Zuletzt bearbeitet 17.09.2026 18:17:10
ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations. A workspace admin can create, view, and delete database tables in another workspace by r...
CVE-2026-82871
- EPSS 0.22%
- Veröffentlicht 31.08.2026 08:46:40
- Zuletzt bearbeitet 17.09.2026 18:17:09
ToolJet before v3.16.208 fails to validate organization membership in database read routes, allowing any authenticated user to access other organizations' table schemas and row data. Attackers can supply arbitrary organization IDs in URL parameters t...
CVE-2026-82870
- EPSS 0.22%
- Veröffentlicht 31.08.2026 08:46:39
- Zuletzt bearbeitet 17.09.2026 18:17:09
ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any builder-role user to create, alter, or drop tables in other organizations' databases. Attackers can exploit missing organization-re...
CVE-2026-82869
- EPSS 0.22%
- Veröffentlicht 31.08.2026 08:46:38
- Zuletzt bearbeitet 10.09.2026 15:53:23
ToolJet Database versions before v3.16.44 contain a privilege escalation vulnerability in the join_tables endpoint that grants JOIN_TABLES ability to all authenticated users without role or workspace membership validation. Attackers can read arbitrar...
CVE-2026-73068
- EPSS 0.19%
- Veröffentlicht 11.08.2026 15:02:13
- Zuletzt bearbeitet 09.09.2026 20:46:02
ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.207, the ToolJet Database HTTP API in server/src/modules/tooljet-db/controller.ts authorizes operations agai...
CVE-2026-54344
- EPSS 0.17%
- Veröffentlicht 08.07.2026 15:08:19
- Zuletzt bearbeitet 26.08.2026 16:36:15
ToolJet is an open-source low-code platform for building internal tools. Prior to 3.20.180, ToolJet's render preview deployment workflow interpolates github.event.comment.body directly into a bash conditional in a run step, allowing any GitHub user w...
CVE-2026-55411
- EPSS 0.13%
- Veröffentlicht 25.06.2026 16:08:14
- Zuletzt bearbeitet 25.06.2026 19:16:42
ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.1780-lts, the authenticated endpoint POST /api/data-sources/decrypt returns the decrypted plaintext for any ...