Zero Day Monitor
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
1483 articles · 105578 vulns · 38/41 feeds (7d)
← Back to list
5.3
CVE-2026-34411EXPLOITED
appsmith · appsmith

Appsmith < 1.98 Unauthenticated Instance Configuration Disclosure via Management APIs

Description

Appsmith versions prior to 1.98 expose sensitive instance management API endpoints without authentication. Unauthenticated attackers can query endpoints like /api/v1/consolidated-api/view and /api/v1/tenants/current to retrieve configuration metadata, license information, and unsalted SHA-256 hashes of admin email domains for reconnaissance and targeted attack planning.

Affected Products

VendorProductVersions
appsmithappsmith0, 1.97.x

References

  • https://github.com/appsmithorg/appsmith/security/advisories/GHSA-qvvc-prjx-f85j(vendor-advisory, patch)
  • https://www.vulncheck.com/advisories/appsmith-unauthenticated-instance-configuration-disclosure-via-management-apis(third-party-advisory)

Related News (1 articles)

Tier C
VulDB3h ago
CVE-2026-34411 | Appsmith up to 1.97.x API Endpoint view missing authentication (GHSA-qvvc-prjx-f85j)
→ No new info (linked only)
CVSS 3.15.3 CRITICAL
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-306
Published3/27/2026
Last enriched2h agov2
Trending Score59
Source articles1
Independent1
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Version History

v2
Last enriched 2h ago
v2Tier C2h ago

Updated affected versions to 1.97.x, changed severity to CRITICAL, and noted that the exploit is not available.

affectedVersionsseverityactivelyExploited
via VulDB
v18h ago

Initial creation