<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-82871 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-82871/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 31 Aug 2026 11:17:20 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-82871/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>ToolJet Multi-Tenancy Broken Access Control</title><link>https://feed.craftedsignal.io/briefs/2026-08-tooljet-id-bypass/</link><pubDate>Mon, 31 Aug 2026 11:17:20 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-tooljet-id-bypass/</guid><description>ToolJet versions prior to 3.16.208 are vulnerable to broken access control, allowing authenticated builder-role users to perform unauthorized database operations across tenant boundaries.</description><content:encoded><![CDATA[<p>ToolJet versions before 3.16.208 contain a critical vulnerability in its multi-tenancy implementation related to the validation of organization ownership. The application fails to properly verify the 'organizationId' during database write and destroy operations. This oversight allows a user assigned the 'builder' role within one organization to interact with, modify, or destroy database tables belonging to different organizations hosted on the same instance. This vulnerability poses a severe risk to data integrity and availability in shared multi-tenant deployments, as it permits unauthorized schema manipulation, arbitrary data insertion, and permanent deletion of tenant data across organization boundaries. Defenders should prioritize patching instances to version 3.16.208 or later to enforce tenant isolation.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for cross-tenant data exfiltration, unauthorized modification of sensitive business data, and permanent loss of database tables. This vulnerability is particularly impactful for organizations hosting multiple internal teams or clients on a single shared ToolJet instance, as it undermines the fundamental multi-tenancy security model.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all ToolJet deployments to version 3.16.208 or later immediately to patch CVE-2026-82870.</li>
<li>Review application access logs for any database-related API requests involving IDs belonging to organizations outside of the user's assigned scope.</li>
<li>Audit the list of users currently assigned the 'builder' role and restrict access to strictly verified users until the patch is applied.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>webserver</category><category>broken-access-control</category><category>vulnerability</category><category>web-application-vulnerability</category><category>authorization-bypass</category><category>privilege-escalation</category><category>web-application</category><category>authentication-bypass</category><category>cve-2026-82871</category></item></channel></rss>