MEDIUM 5.3 NVD
CVE-2026-82873
ToolJet through 3.0.0-ee-beta.2 contains authorization bypass vulnerabilities in the POST /api/v2/resources/export endpoint that allow authenticated users to di
ToolJet through 3.0.0-ee-beta.2 contains authorization bypass vulnerabilities in the POST /api/v2/resources/export endpoint that allow authenticated users to disclose TooljetDB table schemas across workspace boundaries and export app definitions across granular permission boundaries. Attackers can supply a body-provided organization_id parameter to access schemas from other workspaces, or bypass per-app authorization gates to export restricted app definitions within their workspace.
References
- https://github.com/ToolJet/ToolJet/security/advisories/GHSA-pqfh-276q-w3cp
- https://www.vulncheck.com/advisories/tooljet-through-3.0.0-ee-beta-2-cross-workspace-schem
- https://github.com/ToolJet/ToolJet/security/advisories/GHSA-pqfh-276q-w3cp
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-08-31 via NVD.
vulnfeed aggregates 11521 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.