VulnSea

ToolJet vulnerabilities

CVEs whose affected-version data names the ToolJet package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-82875Medium· 5.5PoC
3w ago

ToolJet before v3.16.208 contains an authorization bypass vulnerability in TooljetDB controller endpoints that accept organizationId from URL path without verifying it matches the authenticated user's workspace

ToolJet before v3.16.208 contains an authorization bypass vulnerability in TooljetDB controller endpoints that accept organizationId from URL path without verifying it matches the authenticated user's workspace. Authenticated users can e…

TwilightToolJet · ToolJetEPSS 0.14%via NVD
CVE-2026-82870Critical· 9.6PoC
3w ago

ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any builder-role user to create, alter, or drop tables in other organizations' databases

ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any builder-role user to create, alter, or drop tables in other organizations' databases. Attackers can exploit missing or…

AbyssalToolJet · ToolJetEPSS 0.22%via NVD
CVE-2026-82874Critical· 9.9
3w ago

ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path parameter of tooljet-db endpoints, allowing any Builder user to read, modify, and delete tables across te…

ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path parameter of tooljet-db endpoints, allowing any Builder user to read, modify, and delete tables across te…

MidnightToolJet · ToolJetEPSS 0.25%via NVD
CVE-2026-82872Critical· 9.1PoC
3w ago

ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations

ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations. A workspace admin can create, view, and delete database tables in another w…

AbyssalToolJet · ToolJetEPSS 0.26%via NVD
CVE-2026-82871High· 7.7PoC
3w ago

ToolJet before v3.16.208 fails to validate organization membership in database read routes, allowing any authenticated user to access other organizations' table schemas and row data

ToolJet before v3.16.208 fails to validate organization membership in database read routes, allowing any authenticated user to access other organizations' table schemas and row data. Attackers can supply arbitrary organization IDs in URL…

MidnightToolJet · ToolJetEPSS 0.22%via NVD
ToolJet vulnerabilities (CVEs) · VulnSea