Impact
ToolJet instances running versions prior to 3.16.208 contain an authorization flaw in the database read routes; the system does not verify that the authenticated user belongs to the organization whose data is being requested. An attacker who has valid credentials can supply arbitrary organization identifiers in the URL parameters. This allows the attacker to enumerate table schemas, view column names, and run join queries that return full rows of data from other organizations, resulting in a significant breach of confidentiality and potential data loss for those organizations.
Affected Systems
The vulnerability affects ToolJet, specifically all releases before v3.16.208. Users deploying ToolJet 3.16.207 or earlier are susceptible until they update to the patched version.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity, and the lack of EPSS data suggests that the exploitation probability is not formally quantified but remains a considerable risk. The vulnerability is not yet listed in CISA KEV, but because an authenticated attacker can target any organization in the platform, the attack vector is likely through the web interface or API. The lack of member validation means that once authenticated, the attacker can exhaustively enumerate and read data from all organizations that share the same ToolJet deployment.
OpenCVE Enrichment