{"id":"CVE-2026-82870","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-82870","summary":"ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any builder-role user to create, alter, or drop tables in other organizations'…","details":"ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any builder-role user to create, alter, or drop tables in other organizations' databases. Attackers can exploit missing organization-resolving guards to permanently delete tables, insert arbitrary data, and modify schemas across tenant boundaries on shared instances.","published":"2026-08-31T09:17:07.863","modified":"2026-08-31T09:17:07.863","cvss":{"score":9.6,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://github.com/ToolJet/ToolJet/security/advisories/GHSA-xr3w-r926-xfmm"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/tooljet-before-3.16.208-cross-tenant-database-manipulation"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-31T09:17:07.863"}}