Executive brief
ToolJet is an open-source low-code platform that allows users to build applications and manage databases. The vulnerability allows any authenticated user with Builder privileges to read, modify, or delete database tables belonging to other organizations on the same instance by bypassing tenant isolation checks. Attackers can discover victim organization IDs from publicly shared apps, then exploit database schema endpoints to exfiltrate data, plant malicious tables, corrupt schemas, or permanently destroy data in unrelated organizations.
Technical details
The vulnerability is a cross-tenant authorization bypass (CWE-639) in the tooljet-db controller (/server/src/modules/tooljet-db/controller.ts). The root cause is that all schema operation endpoints (create table, drop table, add/drop columns, etc.) accept an organizationId path parameter that is passed directly to backend operations without validating that the authenticated user belongs to that organization. The ability factory only checks the user's role against the tj-workspace-id HTTP header (user's own workspace) and never cross-validates it against the path parameter. Any authenticated Builder user can craft requests with arbitrary organizationId values to perform read and write operations on other tenants' databases. Victim organization IDs are discoverable pre-authentication via GET /api/apps/slugs/:slug on public apps, which leak the owning organization's UUID. The fix is available in v3.16.208, which adds proper tenant validation similar to the organization-validate guard already used in data-sources controllers.
Affected products
- ToolJet ToolJet before v3.16.208
Timeline
- 2026-08-31: disclosed
- 2026-08-07: patched: Fix released in v3.16.208