Zero Day Monitor
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
1483 articles · 105579 vulns · 38/41 feeds (7d)
← Back to list
5.3
CVE-2026-34411EXPLOITED
appsmith · appsmith

Appsmith < 1.98 Unauthenticated Instance Configuration Disclosure via Management APIs

Description

Appsmith versions prior to 1.98 expose sensitive instance management API endpoints without authentication. Unauthenticated attackers can query endpoints like /api/v1/consolidated-api/view and /api/v1/tenants/current to retrieve configuration metadata, license information, and unsalted SHA-256 hashes of admin email domains for reconnaissance and targeted attack planning.

Affected Products

VendorProductVersions
appsmithappsmith0, 1.97.x

References

  • https://github.com/appsmithorg/appsmith/security/advisories/GHSA-qvvc-prjx-f85j(vendor-advisory, patch)
  • https://www.vulncheck.com/advisories/appsmith-unauthenticated-instance-configuration-disclosure-via-management-apis(third-party-advisory)

Related News (1 articles)

Tier C
VulDB5h ago
CVE-2026-34411 | Appsmith up to 1.97.x API Endpoint view missing authentication (GHSA-qvvc-prjx-f85j)
→ No new info (linked only)
CVSS 3.15.3 CRITICAL
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-306
Published3/27/2026
Last enriched5h agov2
Trending Score59
Source articles1
Independent1
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Version History

v2
Last enriched 5h ago
v2Tier C5h ago

Updated affected versions to 1.97.x, changed severity to CRITICAL, and noted that the exploit is not available.

affectedVersionsseverityactivelyExploited
via VulDB
v110h ago

Initial creation