Impact
ToolJet before v3.16.208 contains an authorization flaw that allows authenticated users to access tenant data that they do not belong to. The flaw arises because the system does not verify that the authenticated user’s organization matches the organizationId supplied in the tooljet-db endpoints. An attacker who has Builder‑role credentials, or who gains access to a vulnerable account, can read, modify, and delete tables in other tenants, causing loss of confidentiality and integrity of tenant data and potentially leading to data loss if tables are destroyed.
Affected Systems
The vulnerability exists in ToolJet release versions prior to 3.16.208. Users of ToolJet before version 3.16.208 are at risk; upgrading to 3.16.208 or later removes the flaw.
Risk and Exploitability
The CVSS score is 2.4, indicating low severity, and the EPSS score is not available; the vulnerability is not listed in CISA KEV. Exploitation requires a legitimate Builder user account and knowledge of a victim organization ID. Attackers can harvest organization IDs from public application endpoints and then use schema operation endpoints to enumerate, create, corrupt, or delete tables across tenants. Although the low CVSS score suggests limited risk, the potential for cross‑tenant data exposure makes timely remediation advisable.
OpenCVE Enrichment