← Back to overview

ToolJet versions before v3.16.208 contain a critical authorization flaw where the organizationId ownership is not validated in database write and destroy routes. This allows any authenticated user with a builder role to create, alter, or drop tables belonging to other organizations on shared instances. The missing organization-resolving guards enable cross-tenant boundary violations, permitting attackers to permanently delete tables, insert arbitrary data, and modify database schemas. The vulnerability poses a serious risk to multi-tenant deployments of ToolJet. Organizations using shared ToolJet instances should upgrade to v3.16.208 or later immediately to remediate the issue.

Affected products

  • ToolJet before v3.16.208

Related CVE's

  • CVE-2026-82870

Categories

  • Database & Storage
  • Enterprise Applications
  • Identity & Access
  • Web Technologies