ToolJet versions before v3.16.208 contain a critical authorization flaw where the organizationId ownership is not validated in database write and destroy routes. This allows any user with a builder role to create, alter, or drop tables belonging to other organizations in shared instances. The missing organization-resolving guards enable attackers to cross tenant boundaries and permanently delete tables, insert arbitrary data, and modify schemas. This is a multi-tenant isolation failure that poses significant risks to shared ToolJet deployments. Organizations using ToolJet in a multi-tenant configuration should upgrade to v3.16.208 or later immediately to remediate the vulnerability.