Appsmith versions prior to 1.98 expose sensitive instance management API endpoints without authentication. Unauthenticated attackers can query endpoints like /api/v1/consolidated-api/view and /api/v1/tenants/current to retrieve configuration metadata, license information, and unsalted SHA-256 hashes of admin email domains for reconnaissance and targeted attack planning.
References
| Link | Resource |
|---|---|
| https://github.com/appsmithorg/appsmith/security/advisories/GHSA-qvvc-prjx-f85j | Exploit Third Party Advisory |
| https://www.vulncheck.com/advisories/appsmith-unauthenticated-instance-configuration-disclosure-via-management-apis | Third Party Advisory |
Configurations
History
31 Mar 2026, 16:26
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/appsmithorg/appsmith/security/advisories/GHSA-qvvc-prjx-f85j - Exploit, Third Party Advisory | |
| References | () https://www.vulncheck.com/advisories/appsmith-unauthenticated-instance-configuration-disclosure-via-management-apis - Third Party Advisory | |
| CPE | cpe:2.3:a:appsmith:appsmith:*:*:*:*:*:*:*:* | |
| First Time |
Appsmith
Appsmith appsmith |
27 Mar 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-27 17:16
Updated : 2026-03-31 16:26
NVD link : CVE-2026-34411
Mitre link : CVE-2026-34411
CVE.ORG link : CVE-2026-34411
JSON object : View
Products Affected
appsmith
- appsmith
CWE
CWE-306
Missing Authentication for Critical Function
