Home

Description

Appsmith versions prior to 1.98 expose sensitive instance management API endpoints without authentication. Unauthenticated attackers can query endpoints like /api/v1/consolidated-api/view and /api/v1/tenants/current to retrieve configuration metadata, license information, and unsalted SHA-256 hashes of admin email domains for reconnaissance and targeted attack planning.

PUBLISHED Reserved 2026-03-27 | Published 2026-03-27 | Updated 2026-03-27 | Assigner VulnCheck




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

MEDIUM: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Problem types

CWE-306 Missing Authentication for Critical Function

Product status

Default status
unaffected

Any version before 1.98.0
affected

Credits

Neo by ProjectDiscovery (https://neo.projectdiscovery.io) finder

References

github.com/...psmith/security/advisories/GHSA-qvvc-prjx-f85j vendor-advisory patch

www.vulncheck.com/...guration-disclosure-via-management-apis third-party-advisory

cve.org (CVE-2026-34411)

nvd.nist.gov (CVE-2026-34411)

Download JSON