---
id: CVE-2026-82874
title: >-
  ToolJet before v3.16.208 fails to validate that authenticated users belong to
  the organization specified in the organizationId path parameter of tooljet-db
  endpoints, allowing any Builder user to read, modify, and delete tables across
  te…
summary: >-
  ToolJet before v3.16.208 fails to validate that authenticated users belong to
  the organization specified in the organizationId path parameter of tooljet-db
  endpoints, allowing any Builder user to read, modify, and delete tables across
  te…
severity: critical
cvss: 9.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-639
vendor: ToolJet
product: ToolJet
affected:
  - ToolJet < 3.16.208
published: '2026-08-31'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T19:17:04.860'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82874'
references:
  - url: 'https://github.com/ToolJet/ToolJet/security/advisories/GHSA-w3hx-rg9g-mw5c'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/tooljet-before-3.16.208-cross-tenant-authorization-bypass-via-tooljet-db
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-31T16:23:06.111388Z'
epss: 0.00442
epssPercentile: 0.35713
ingestedAt: '2026-09-10T16:57:28.697Z'
---

## Overview

ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path parameter of tooljet-db endpoints, allowing any Builder user to read, modify, and delete tables across tenant boundaries. Attackers can extract victim organization IDs from public app endpoints, then exploit schema operation endpoints to disclose table schemas, plant malicious tables, corrupt existing schemas, or permanently destroy victim data without any relationship to the target organization.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
