Junglewise Threat Intelligence

Saltcorn tenant privilege escalation via role context mismatch

Severity: medium · CVSS 4 · Published 2026-04-22

Vendors: Saltcorn.

Executive brief

Saltcorn is an open-source no-code application platform that allows organizations to build and manage database-driven applications. The vulnerability allows a tenant administrator who is logged into their isolated tenant space to create new tenants at the root domain level by appending /tenant/create to their URL, effectively gaining administrative control over the entire Saltcorn installation. This breaks the multi-tenant isolation model and allows any tenant admin to perform privileged operations they should not have access to.

Technical details

The vulnerability is an authorization bypass (CWE-863) caused by incorrect role validation during tenant creation. When a tenant admin navigates to /tenant/create, the system reads the user's role from their current tenant context (where they hold admin role) rather than validating the role against the root domain's authorization rules. This context mismatch allows the attacker to create tenants in the root domain's PUBLIC SCHEMA instead of within their isolated tenant schema. The attack requires the attacker to be authenticated as an admin in their own tenant space and have network access to the application; exploitation is straightforward and does not require complex preconditions. The issue affects @saltcorn/data versions before 1.4.4, 1.5.x before 1.5.2, and 1.6.x before 1.6.0-beta.2, with patches available for all affected branches.

Affected products

  • Saltcorn @saltcorn/data <1.4.4, 1.5.0-1.5.1, 1.6.0-alpha.0 to 1.6.0-beta.1

Timeline

  • 2026-04-22: disclosed: Advisory published on GitHub and OSV
  • 2026-04-22: patched: Patches released: 1.4.4, 1.5.2, 1.6.0-beta.2

References