<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>ToolJet - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/tooljet/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 31 Aug 2026 11:18:13 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/tooljet/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>ToolJet Database Privilege Escalation in join_tables Endpoint</title><link>https://feed.craftedsignal.io/briefs/2026-08-tooljet-privesc/</link><pubDate>Mon, 31 Aug 2026 11:18:13 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-tooljet-privesc/</guid><description>ToolJet Database versions prior to 3.16.44 contain a privilege escalation vulnerability in the join_tables endpoint that permits unauthenticated access to arbitrary tables across workspaces.</description><content:encoded><![CDATA[<p>ToolJet Database versions before v3.16.44 contain a privilege escalation vulnerability within the join_tables endpoint. This flaw allows any authenticated user to perform unauthorized read operations on tables belonging to workspaces they do not belong to or have permissions for. The root cause is a failure in the application logic to validate workspace membership or user role permissions when a request is made to the join_tables interface. By manipulating workspace identifiers within the request path, an attacker can enumerate and exfiltrate data from arbitrary tables across the entire application instance. This issue presents a significant data confidentiality risk, particularly in multi-tenant or collaborative enterprise environments where strict isolation between workspace data is expected.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability enables authenticated users to bypass workspace-level access controls and read sensitive information from any database table managed by the ToolJet instance. This could lead to massive unauthorized data exfiltration in multi-tenant environments.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Upgrade all ToolJet Database installations to version 3.16.44 or later immediately. Access logs should be audited for anomalous HTTP requests to the join_tables endpoint where the workspace identifier in the path deviates from the user's authorized workspace context.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item><item><title>ToolJet Multi-Tenancy Broken Access Control</title><link>https://feed.craftedsignal.io/briefs/2026-08-tooljet-id-bypass/</link><pubDate>Mon, 31 Aug 2026 11:17:20 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-tooljet-id-bypass/</guid><description>ToolJet versions prior to 3.16.208 are vulnerable to broken access control, allowing authenticated builder-role users to perform unauthorized database operations across tenant boundaries.</description><content:encoded><![CDATA[<p>ToolJet versions before 3.16.208 contain a critical vulnerability in its multi-tenancy implementation related to the validation of organization ownership. The application fails to properly verify the 'organizationId' during database write and destroy operations. This oversight allows a user assigned the 'builder' role within one organization to interact with, modify, or destroy database tables belonging to different organizations hosted on the same instance. This vulnerability poses a severe risk to data integrity and availability in shared multi-tenant deployments, as it permits unauthorized schema manipulation, arbitrary data insertion, and permanent deletion of tenant data across organization boundaries. Defenders should prioritize patching instances to version 3.16.208 or later to enforce tenant isolation.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for cross-tenant data exfiltration, unauthorized modification of sensitive business data, and permanent loss of database tables. This vulnerability is particularly impactful for organizations hosting multiple internal teams or clients on a single shared ToolJet instance, as it undermines the fundamental multi-tenancy security model.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all ToolJet deployments to version 3.16.208 or later immediately to patch CVE-2026-82870.</li>
<li>Review application access logs for any database-related API requests involving IDs belonging to organizations outside of the user's assigned scope.</li>
<li>Audit the list of users currently assigned the 'builder' role and restrict access to strictly verified users until the patch is applied.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>webserver</category><category>broken-access-control</category><category>vulnerability</category><category>web-application-vulnerability</category><category>authorization-bypass</category><category>privilege-escalation</category><category>web-application</category><category>authentication-bypass</category><category>cve-2026-82871</category></item></channel></rss>