Impact
ToolJet before version 3.16.208 does not enforce ownership checks on its database write and destroy endpoints, so any user with builder permissions can perform CREATE, ALTER, or DROP operations on databases belonging to other organizations. This flaw permits permanent deletion of tables, insertion of arbitrary data, and schema alterations across tenant boundaries, potentially exposing sensitive information and corrupting data integrity for multiple independent customers.
Affected Systems
The vulnerability affects all installations of ToolJet where the product version is earlier than 3.16.208 and the instance is shared among multiple organizations. Any orchestrated or accidental misuse of the builder role can reach the affected tenant databases.
Risk and Exploitability
The CVSS score of 7 indicates a high‑impact vulnerability. While EPSS data is not available, the lack of a KEV listing does not diminish the potential seriousness in a shared‑tenant deployment. Exploitation requires only that an attacker obtain or abuse builder‑level credentials, a role that may be granted to internal developers or external contributors. Once the condition is met, the attacker can cause irreversible data loss or manipulation across other tenants without additional system access.
OpenCVE Enrichment