---
id: CVE-2026-82875
title: >-
  ToolJet before v3.16.208 contains an authorization bypass vulnerability in
  TooljetDB controller endpoints that accept organizationId from URL path
  without verifying it matches the authenticated user's workspace
summary: >-
  ToolJet before v3.16.208 contains an authorization bypass vulnerability in
  TooljetDB controller endpoints that accept organizationId from URL path
  without verifying it matches the authenticated user's workspace. Authenticated
  users can e…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-863
vendor: ToolJet
product: ToolJet
affected:
  - ToolJet < 3.16.208
published: '2026-08-31'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T18:17:10.377'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82875'
references:
  - url: 'https://github.com/ToolJet/ToolJet/security/advisories/GHSA-cx42-x23w-vhvf'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/tooljet-before-3.16.208-authorization-bypass-via-organizationid
    label: disclosure@vulncheck.com
  - url: 'https://github.com/ToolJet/ToolJet/security/advisories/GHSA-cx42-x23w-vhvf'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-31T14:45:00.939420Z'
epss: 0.00219
epssPercentile: 0.10923
ingestedAt: '2026-09-17T18:25:15.987Z'
---

## Overview

ToolJet before v3.16.208 contains an authorization bypass vulnerability in TooljetDB controller endpoints that accept organizationId from URL path without verifying it matches the authenticated user's workspace. Authenticated users can enumerate, create, rename, and delete TooljetDB tables in any other workspace by manipulating the organizationId parameter in requests.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
