PT-2026-28632 · Appsmith · Appsmith

·

CVE-2026-34411

·

Published

2026-03-27

·

Updated

2026-04-01

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Appsmith versions prior to 1.98
Description Sensitive instance management API endpoints are exposed without authentication. Unauthenticated attackers can query endpoints such as '/api/v1/consolidated-api/view' and '/api/v1/tenants/current' to retrieve configuration metadata, license information, and unsalted SHA-256 hashes of admin email domains for reconnaissance and targeted attack planning.
Recommendations Update to version 1.98 or later.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-APPSMITH-2026-34411
CVE-2026-34411
GHSA-QVVC-PRJX-F85J

Affected Products

Appsmith