← Back to overview

ToolJet versions before v3.16.208 contain a critical authorization flaw where the organizationId ownership is not validated in database write and destroy routes. This allows any user with a builder role to create, alter, or drop tables belonging to other organizations in shared instances. The missing organization-resolving guards enable attackers to cross tenant boundaries and permanently delete tables, insert arbitrary data, and modify schemas. This is a multi-tenant isolation failure that poses significant risks to shared ToolJet deployments. Organizations using ToolJet in a multi-tenant configuration should upgrade to v3.16.208 or later immediately to remediate the vulnerability.

Affected products

  • ToolJet

Related CVE's

  • CVE-2026-82870

Categories

  • Database & Storage
  • Enterprise Applications
  • Identity & Access
  • Web Technologies