PT-2026-83746 · Unknown · Database Toolset
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ToolJet Database versions prior to 3.16.44
Description
A privilege escalation issue exists in the '/join tables' endpoint. The system fails to validate the role or workspace membership of authenticated users, granting them the JOIN TABLES ability. This allows an authenticated attacker to read arbitrary tables from any workspace by providing the target workspace identifiers in the request path while using their own valid credentials.
Recommendations
Update ToolJet Database to version 3.16.44 or later.
Restrict access to the '/join tables' endpoint as a temporary mitigation measure.
Fix
LPE
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Database Toolset