Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

ToolJet authorization bypass allows cross-organization data access

ToolJet prior to version 3.20.207 contains an authorization bypass vulnerability in its Database HTTP API that allows authenticated users to access, modify, and delete data across organization boundaries by manipulating the tj-workspace-id header.

Disclosed 11 August 2026 · Record updated 13 September 2026

Impact

Authenticated users can view and modify tables, schemas, and rows across different organizations, including creating, altering, bulk populating, or dropping tables in other tenants.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-73068