{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/tooljet/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:tooljet:database:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.7,"id":"CVE-2026-82869"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ToolJet Database (\u003c 3.16.44)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["ToolJet"],"content_html":"\u003cp\u003eToolJet Database versions before v3.16.44 contain a privilege escalation vulnerability within the join_tables endpoint. This flaw allows any authenticated user to perform unauthorized read operations on tables belonging to workspaces they do not belong to or have permissions for. The root cause is a failure in the application logic to validate workspace membership or user role permissions when a request is made to the join_tables interface. By manipulating workspace identifiers within the request path, an attacker can enumerate and exfiltrate data from arbitrary tables across the entire application instance. This issue presents a significant data confidentiality risk, particularly in multi-tenant or collaborative enterprise environments where strict isolation between workspace data is expected.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability enables authenticated users to bypass workspace-level access controls and read sensitive information from any database table managed by the ToolJet instance. This could lead to massive unauthorized data exfiltration in multi-tenant environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpgrade all ToolJet Database installations to version 3.16.44 or later immediately. Access logs should be audited for anomalous HTTP requests to the join_tables endpoint where the workspace identifier in the path deviates from the user's authorized workspace context.\u003c/p\u003e\n","date_modified":"2026-08-31T11:18:13Z","date_published":"2026-08-31T11:18:13Z","id":"https://feed.craftedsignal.io/briefs/2026-08-tooljet-privesc/","summary":"ToolJet Database versions prior to 3.16.44 contain a privilege escalation vulnerability in the join_tables endpoint that permits unauthenticated access to arbitrary tables across workspaces.","title":"ToolJet Database Privilege Escalation in join_tables Endpoint","url":"https://feed.craftedsignal.io/briefs/2026-08-tooljet-privesc/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:tooljet:tooljet:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.6,"id":"CVE-2026-82870"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ToolJet (\u003c 3.16.208)"],"_cs_severities":["critical"],"_cs_tags":["webserver","broken-access-control","vulnerability","web-application-vulnerability","authorization-bypass","privilege-escalation","web-application","authentication-bypass","cve-2026-82871"],"_cs_type":"advisory","_cs_vendors":["ToolJet"],"content_html":"\u003cp\u003eToolJet versions before 3.16.208 contain a critical vulnerability in its multi-tenancy implementation related to the validation of organization ownership. The application fails to properly verify the 'organizationId' during database write and destroy operations. This oversight allows a user assigned the 'builder' role within one organization to interact with, modify, or destroy database tables belonging to different organizations hosted on the same instance. This vulnerability poses a severe risk to data integrity and availability in shared multi-tenant deployments, as it permits unauthorized schema manipulation, arbitrary data insertion, and permanent deletion of tenant data across organization boundaries. Defenders should prioritize patching instances to version 3.16.208 or later to enforce tenant isolation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for cross-tenant data exfiltration, unauthorized modification of sensitive business data, and permanent loss of database tables. This vulnerability is particularly impactful for organizations hosting multiple internal teams or clients on a single shared ToolJet instance, as it undermines the fundamental multi-tenancy security model.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all ToolJet deployments to version 3.16.208 or later immediately to patch CVE-2026-82870.\u003c/li\u003e\n\u003cli\u003eReview application access logs for any database-related API requests involving IDs belonging to organizations outside of the user's assigned scope.\u003c/li\u003e\n\u003cli\u003eAudit the list of users currently assigned the 'builder' role and restrict access to strictly verified users until the patch is applied.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-31T11:18:23Z","date_published":"2026-08-31T11:17:20Z","id":"https://feed.craftedsignal.io/briefs/2026-08-tooljet-id-bypass/","summary":"ToolJet versions prior to 3.16.208 are vulnerable to broken access control, allowing authenticated builder-role users to perform unauthorized database operations across tenant boundaries.","title":"ToolJet Multi-Tenancy Broken Access Control","url":"https://feed.craftedsignal.io/briefs/2026-08-tooljet-id-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - ToolJet","version":"https://jsonfeed.org/version/1.1"}