CVE-2026-73068 | ToolJet up to 3.20.206 ToolJet Database HTTP API controller.ts organizationId improper authorization
A vulnerability, which was classified as critical, was found in ToolJet up to 3.20.206. This impacts an unknown function of the file server/src/modules/tooljet-db/controller.ts of the component ToolJet Database HTTP API. Such manipulation of the argument organizationId leads to improper authorization.
This vulnerability is documented as CVE-2026-73068. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.VulDB Recent EntriesRead More