Impact
The vulnerability arises in the join_tables endpoint of ToolJet Database versions before 3.16.44, allowing any authenticated user to perform JOIN_TABLES operations without checking the user's role or workspace membership. This capability enables the user to read arbitrary tables in any workspace simply by providing the victim workspace identifier in the request path. Consequently, the attacker can gain unauthorized access to sensitive data across workspaces, breaching confidentiality and potentially impacting data integrity.
Affected Systems
ToolJet, ToolJet Database versions earlier than 3.16.44 are affected. Users running those versions are susceptible to the privilege escalation described.
Risk and Exploitability
The CVSS score of 8.2 classifies this as a high‑severity issue. EPSS data is not available, and the vulnerability is not listed in CISA's KEV catalog. Inferred from the description, the attack vector requires the attacker to be an authenticated user; there is no mention of remote code execution or denial of service. An attacker with valid credentials could exploit join_tables to read tables from any workspace, meaning the attack path is straightforward for users who already have access to the system.
OpenCVE Enrichment