CRITICAL 9.1 CVE-2026-82872 Published 31 Aug 2026

ToolJet API Path Tampering Vulnerability

Worried this affects one of your servers?

ToolJet versions before 3.16.208 do not validate the organizationId path parameter in table-management API requests.

ToolJet allows workspace admins to perform unauthorized DB table operations in other workspaces by manipulating this parameter.

Reference: CVE-2026-82872 on NVD

← Back to Security News