Junglewise Threat Intelligence

CVE-2026-55411: ToolJet cross-tenant IDOR in credential decryption endpoint

CVE-2026-55411 · Severity: medium · CVSS 6.8 · Published 2026-06-25

Technologies: ToolJet. Vendors: ToolJet.

Executive brief

ToolJet is an open-source platform used to build internal business tools and AI agents. A security flaw allows any logged-in user to view sensitive credentials, such as database passwords and API keys, belonging to other organizations on the same server. This represents a significant breach of privacy and could allow an attacker to gain unauthorized access to a company's external data sources and connected services.

Technical details

An Insecure Direct Object Reference (IDOR) exists in the 'POST /api/data-sources/decrypt' endpoint. Unlike other data-source routes in ToolJet, this specific handler lacks the 'ValidateDataSourceGuard' and does not perform organization-level scoping. The underlying 'CredentialsService.getValue()' function retrieves credentials based solely on the provided 'credential_id' without verifying if the requesting user belongs to the organization that owns the secret. An authenticated attacker can exploit this by supplying a 'credential_id' in the request body to receive the plaintext value of secrets like database passwords or OAuth tokens. The issue is fixed in version 3.20.1780-lts.

Affected products

  • ToolJet ToolJet < 3.20.1780-lts

Timeline

  • 2026-06-12: advisory: GitHub Security Advisory published
  • 2026-06-25: disclosed: NVD publication date

References

Related threats