VulnSea

ToolJet has 5 CVEs on record. 5 were published in the last 90 days. The busiest recent month was August 2026 with 5. The median CVSS is 9.1 (critical), with 3 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-639 (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
9.1
Publish → KEV
Last 90 days
5 prev 0

Products

  • ToolJet 5
5
Total CVEs
3
Critical
0
CISA KEV
0
Exploited

ToolJet vulnerabilities

CVEs affecting ToolJet, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2026-82875Medium· 5.5PoC
3w ago

ToolJet before v3.16.208 contains an authorization bypass vulnerability in TooljetDB controller endpoints that accept organizationId from URL path without verifying it matches the authenticated user's workspace

ToolJet before v3.16.208 contains an authorization bypass vulnerability in TooljetDB controller endpoints that accept organizationId from URL path without verifying it matches the authenticated user's workspace. Authenticated users can e…

TwilightToolJet · ToolJetEPSS 0.14%via NVD
CVE-2026-82870Critical· 9.6PoC
3w ago

ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any builder-role user to create, alter, or drop tables in other organizations' databases

ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any builder-role user to create, alter, or drop tables in other organizations' databases. Attackers can exploit missing or…

AbyssalToolJet · ToolJetEPSS 0.22%via NVD
CVE-2026-82874Critical· 9.9
3w ago

ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path parameter of tooljet-db endpoints, allowing any Builder user to read, modify, and delete tables across te…

ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path parameter of tooljet-db endpoints, allowing any Builder user to read, modify, and delete tables across te…

MidnightToolJet · ToolJetEPSS 0.25%via NVD
CVE-2026-82872Critical· 9.1PoC
3w ago

ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations

ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations. A workspace admin can create, view, and delete database tables in another w…

AbyssalToolJet · ToolJetEPSS 0.26%via NVD
CVE-2026-82871High· 7.7PoC
3w ago

ToolJet before v3.16.208 fails to validate organization membership in database read routes, allowing any authenticated user to access other organizations' table schemas and row data

ToolJet before v3.16.208 fails to validate organization membership in database read routes, allowing any authenticated user to access other organizations' table schemas and row data. Attackers can supply arbitrary organization IDs in URL…

MidnightToolJet · ToolJetEPSS 0.22%via NVD
ToolJet vulnerabilities (CVEs) · VulnSea