PatchSiren cyber security CVE debrief
CVE-2026-82869 ToolJet CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-31T09:17:07.693Z and has not been modified since then. CVE-2026-82869 is a privilege escalation vulnerability in the join_tables endpoint of ToolJet Database versions before v3.16.44. The vulnerability allows all authenticated users to read arbitrary ToolJet Database tables from any workspace by supplying victim workspace identifiers in the request path while authenticating with their own workspace credentials. This vulnerability has a CVSS score of 8.2 and is classified as HIGH severity. Users and administrators of ToolJet Database versions before v3.16.44 should be aware of this vulnerability and take steps to mitigate it. This includes verifying version numbers, restricting access to the join_tables endpoint, and implementing role and workspace membership validation. Affected operators, platforms, and security teams should review and act on this vulnerability to prevent potential exploitation.
- Vendor
- ToolJet
- Product
- Unknown
- CVSS
- HIGH 8.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-31
- Original CVE updated
- 2026-08-31
- Advisory published
- 2026-08-31
- Advisory updated
- 2026-08-31
Who should care
Users and administrators of ToolJet Database versions before v3.16.44 should be aware of this vulnerability and take steps to mitigate it. This includes verifying version numbers, restricting access to the join_tables endpoint, and implementing role and workspace membership validation. Affected operators, platforms, and security teams should review and act on this vulnerability to prevent potential exploitation.
Technical summary
CVE-2026-82869 is a privilege escalation vulnerability in the join_tables endpoint of ToolJet Database versions before v3.16.44. The vulnerability allows all authenticated users to read arbitrary ToolJet Database tables from any workspace by supplying victim workspace identifiers in the request path while authenticating with their own workspace credentials. This vulnerability has a CVSS score of 8.2 and is classified as HIGH severity.
Defensive priority
Authenticated users may be able to escalate privileges and read arbitrary ToolJet Database tables by exploiting a vulnerability in the join_tables endpoint.
Recommended defensive actions
- Inventory and verify ToolJet Database versions, checking for version v3.16.44 or later.
- Restrict access to the join_tables endpoint to authorized users and workspaces.
- Implement role and workspace membership validation for JOIN_TABLES ability.
- Monitor for suspicious activity related to the join_tables endpoint.
- Apply vendor-provided patches or updates.
Evidence notes
The CVE-2026-82869 vulnerability affects ToolJet Database versions before v3.16.44. The vulnerability grants JOIN_TABLES ability to all authenticated users without role or workspace membership validation. Evidence is based on official CVE Program and NVD records, as well as advisories from [email protected]. Defenders should verify affected deployments, review official advisories, and plan vendor-supported updates or mitigations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-82869 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-82869
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-82869 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-82869
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/ToolJet/ToolJet/security/advisories/GHSA-7vj5-wxfm-gmfq
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/tooljet-database-before-3.16.44-privilege-escalation-via-join-tables
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.