ToolJet
7 known vulnerabilities in ToolJet, 1 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-82875 CVSS 5.1 medium ToolJet before v3.16.208 contains an authorization bypass vulnerability in TooljetDB controller endpoints that accept organizationId from…
- CVE-2026-82874 CVSS 9.4 critical ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path…
- CVE-2026-82873 CVSS 5.3 medium ToolJet through 3.0.0-ee-beta.2 contains authorization bypass vulnerabilities in the POST /api/v2/resources/export endpoint that allow…
- CVE-2026-82872 CVSS 7.1 high ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing…
- CVE-2026-82871 CVSS 8.2 high ToolJet before v3.16.208 fails to validate organization membership in database read routes, allowing any authenticated user to access…
- CVE-2026-82870 CVSS 7.0 high ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any builder-role user…
- CVE-2026-82869 CVSS 8.2 high ToolJet Database versions before v3.16.44 contain a privilege escalation vulnerability in the join_tables endpoint that grants JOIN_TABLES…