SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-82874

CRITICAL · CVSS 9.9 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-31 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

ToolJet versions prior to 3.16.208 are vulnerable due to insufficient validation of user organization affiliations, enabling authenticated Builder users to access, modify, and delete data across different tenant boundaries. This critical flaw allows attackers to exploit public app endpoints to extract organization IDs and manipulate database schemas, potentially leading to data disclosure, corruption, or destruction. Organizations using ToolJet should prioritize immediate updates to mitigate this severe risk to their data integrity and security.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82874
Severity
CRITICAL
CVSS
9.9
EPSS
0.26%

Original NVD Description

ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path parameter of tooljet-db endpoints, allowing any Builder user to read, modify, and delete tables across tenant boundaries. Attackers can extract victim organization IDs from public app endpoints, then exploit schema operation endpoints to disclose table schemas, plant malicious tables, corrupt existing schemas, or permanently destroy victim data without any relationship to the target organization.