SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-82869

HIGH · CVSS 7.7 EPSS 0.22% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-31 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

ToolJet Database versions prior to v3.16.44 are vulnerable to a privilege escalation issue in the join_tables endpoint, allowing authenticated users to gain unauthorized access to JOIN_TABLES capabilities without proper role or workspace validation. This flaw enables attackers to read any database tables across different workspaces by manipulating workspace identifiers in their requests. Organizations using affected versions should prioritize patching this vulnerability to prevent potential data exposure and unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82869
Severity
HIGH
CVSS
7.7
EPSS
0.22%

Original NVD Description

ToolJet Database versions before v3.16.44 contain a privilege escalation vulnerability in the join_tables endpoint that grants JOIN_TABLES ability to all authenticated users without role or workspace membership validation. Attackers can read arbitrary ToolJet Database tables from any workspace by supplying victim workspace identifiers in the request path while authenticating with their own workspace credentials.