Beveiligingsadvies

CVE-2026-82872

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-31 08:46:40
Laatst bijgewerkt 2026-09-01 15:07:06
Toegewezen door VulnCheck
CVSS-score 9.1
Status PUBLISHED

Beschrijving

ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations. A workspace admin can create, view, and delete database tables in another workspace by replacing the organizationId parameter in table-management API requests.