← Terug naar overzicht

ToolJet versions before v3.16.208 contain a critical cross-tenant authorization bypass vulnerability in its tooljet-db endpoints. The flaw allows any authenticated Builder user to access, modify, and delete database tables belonging to other organizations without authorization. The vulnerability stems from a failure to validate that the authenticated user belongs to the organization specified in the organizationId path parameter. Attackers can harvest victim organization IDs from public app endpoints and then exploit schema operation endpoints to read table schemas, insert malicious tables, corrupt existing schemas, or permanently delete victim data. This represents a significant multi-tenant isolation failure that could lead to data breaches and data destruction across organizational boundaries. A fix has been released in ToolJet v3.16.208.

Affected products

  • ToolJet before v3.16.208

Related CVE's

  • CVE-2026-82874

Categories

  • Database & Storage
  • Enterprise Applications
  • Identity & Access
  • Web Technologies