CRITICAL
9.1 CVE-2026-82872 Published 31 Aug 2026
ToolJet API Path Tampering Vulnerability
Worried this affects one of your servers?
ToolJet versions before 3.16.208 do not validate the organizationId path parameter in table-management API requests.
ToolJet allows workspace admins to perform unauthorized DB table operations in other workspaces by manipulating this parameter.
Reference: CVE-2026-82872 on NVD
← Back to Security News