ToolJet authorization bypass allows cross-organization data access
ToolJet prior to version 3.20.207 contains an authorization bypass vulnerability in its Database HTTP API that allows authenticated users to access, modify, and delete data across organization boundaries by manipulating the tj-workspace-id header.
Disclosed 11 August 2026 · Record updated 13 September 2026
Impact
Authenticated users can view and modify tables, schemas, and rows across different organizations, including creating, altering, bulk populating, or dropping tables in other tenants.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-73068
