---
id: CVE-2026-82871
title: >-
  ToolJet before v3.16.208 fails to validate organization membership in database
  read routes, allowing any authenticated user to access other organizations'
  table schemas and row data
summary: >-
  ToolJet before v3.16.208 fails to validate organization membership in database
  read routes, allowing any authenticated user to access other organizations'
  table schemas and row data. Attackers can supply arbitrary organization IDs in
  URL…
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-862
vendor: ToolJet
product: ToolJet
affected:
  - ToolJet < 3.16.208
published: '2026-08-31'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T18:17:09.903'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82871'
references:
  - url: 'https://github.com/ToolJet/ToolJet/security/advisories/GHSA-xqqj-pfc2-vf48'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/tooljet-before-3.16.208-cross-organization-data-read-via-database-routes
    label: disclosure@vulncheck.com
  - url: 'https://github.com/ToolJet/ToolJet/security/advisories/GHSA-xqqj-pfc2-vf48'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-02T15:52:35.933498Z'
epss: 0.00407
epssPercentile: 0.32397
ingestedAt: '2026-09-10T16:57:28.696Z'
---

## Overview

ToolJet before v3.16.208 fails to validate organization membership in database read routes, allowing any authenticated user to access other organizations' table schemas and row data. Attackers can supply arbitrary organization IDs in URL parameters to list tables, retrieve column definitions, and execute join queries to read actual stored data from victim organizations.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
