CVE-2026-73068: ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI
Summary
ToolJet, a platform for building internal tools and AI agents, had a security flaw in its database API before version 3.20.207 where it didn't properly check if users belonged to an organization before letting them access its data. An authenticated user (someone with a valid login) could trick the system by using their own workspace ID in a header while targeting another organization's database through API requests, allowing them to see or modify other organizations' tables and data.
Solution / Mitigation
This issue is fixed in version 3.20.207-lts.
Vulnerability Details
5.9(medium)
EPSS: 0.0%
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
adjacent
low
high
none
August 11, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
CVE-2024-27444: langchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-73068
First tracked: August 11, 2026 at 02:09 PM
Classified by LLM (prompt v3) · confidence: 85%