ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.207, the ToolJet Database HTTP API in server/src/modules/tooljet-db/controller.ts authorizes operations against the :organizationId URL path value without verifying that the caller belongs to that organization. JwtAuthGuard validates the tj-workspace-id header against the caller's memberships, while server/src/modules/tooljet-db/ability/index.ts grants VIEW_TABLES, VIEW_TABLE, and JOIN_TABLES without binding them to the path organization. An authenticated user can set tj-workspace-id to the user's own workspace and target another workspace through GET /api/tooljet-db/organizations/:organizationId/tables, GET /api/tooljet-db/organizations/:organizationId/table/:tableName, POST /api/tooljet-db/organizations/:organizationId/join, and the related table-management routes, allowing disclosure of table names, schemas, and rows and allowing tables to be created, altered, bulk populated, or dropped across tenant boundaries. This issue is fixed in version 3.20.207-lts.
CVE-2026-73068
This medium-severity CVE scores 5.9 under a secondary CVSS source (NVD's own analysis pending). EPSS exploit probability: 0.2%, top 92% of all CVEs by exploit prediction. GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).
- Lower severity and no public exploit yet
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 5.9
- EG Score
- 5.9(medium)
- EG Risk
- 43(Track)EG Risk 43/100SSVC: Track
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity59% × 45%Exploitation40% × 40%Automatability0% × 15%Action: Routine — remediate on your standard cadence. - EPSS PROB
- 0%
- EPSS %ILE
- 8%
- KEV
- Not listed
Published
August 11, 2026
Last Modified
August 13, 2026
Advisory Details (4)
Auto-updated Aug 11, 2026v3.20.207-lts
Patch available: ToolJet/ToolJet v3.20.207-lts
https://github.com/ToolJet/ToolJet/releases/tag/v3.20.207-ltscommit 4c1dbef74873 (ToolJet/ToolJet)
Patch available: ToolJet/ToolJet v3.20.207-lts (contains commit 4c1dbef74873)
https://github.com/ToolJet/ToolJet/commit/4c1dbef7487354bd4a2b5e1c633381ea783bf879Cross Tenant TJDB Vulnerabilities
Patch available: ToolJet/ToolJet v3.20.207-lts (PR #17298 merged 2026-08-04)
https://github.com/ToolJet/ToolJet/pull/17298Cross-tenant Broken Access Control in ToolJet Database (tooljet-db): any authenticated user can read and write another organization's tables · Advisory · ToolJet/ToolJet · GitHub
https://github.com/ToolJet/ToolJet/security/advisories/GHSA-h47x-ffhc-xqh8Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 11× in last 7d / 36× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-08-27 22:29 UTCEG score recompute
- 2026-08-27 14:25 UTCEPSS rescore
- 2026-08-26 23:38 UTCEG score recompute
- 2026-08-26 14:47 UTCEPSS rescore
- 2026-08-26 00:45 UTCEG score recompute
- 2026-08-25 13:49 UTCEPSS rescore
- 2026-08-25 01:54 UTCEG score recompute
- 2026-08-23 04:07 UTCEG score recompute
- 2026-08-23 00:19 UTCEPSS rescore
- 2026-08-22 05:15 UTCEG score recompute
- 2026-08-21 23:49 UTCEPSS rescore
- 2026-08-21 06:23 UTCEG score recompute
- 2026-08-20 22:56 UTCEPSS rescore
- 2026-08-20 07:31 UTCEG score recompute
- 2026-08-19 17:04 UTCEPSS rescore
- 2026-08-19 08:39 UTCEG score recompute
- 2026-08-18 13:49 UTCEPSS rescore
- 2026-08-18 13:49 UTCEPSS rescore
- 2026-08-18 09:47 UTCEG score recompute
- 2026-08-17 13:47 UTCEPSS rescore
- 2026-08-17 10:55 UTCEG score recompute
- 2026-08-16 14:56 UTCEPSS rescore
- 2026-08-16 14:56 UTCEPSS rescore
- 2026-08-16 12:03 UTCEG score recompute
- 2026-08-16 02:15 UTCEPSS rescore
Show 11 moreShow fewer
- 2026-08-15 13:12 UTCEG score recompute
- 2026-08-15 01:31 UTCEPSS rescore
- 2026-08-14 14:20 UTCEG score recompute
- 2026-08-13 22:00 UTCEPSS rescore
- 2026-08-13 15:28 UTCEG score recompute
- 2026-08-13 15:16 UTCEG score recompute
- 2026-08-12 15:27 UTCEG score recompute
- 2026-08-12 13:51 UTCEPSS rescore
- 2026-08-11 16:36 UTCEG score recompute
- 2026-08-11 15:21 UTCEG score recompute
- 2026-08-11 15:20 UTCMITRE cvelistV5first tracked
Frequently asked(5)
What is CVE-2026-73068?
When was CVE-2026-73068 disclosed?
Is CVE-2026-73068 actively exploited?
What is the CVSS score of CVE-2026-73068?
How do I remediate CVE-2026-73068?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2026-73068
Is Your Infrastructure Affected by CVE-2026-73068?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.