CVE-2026-34411
EUVD-2026-1672127.03.2026, 17:16
Appsmith versions prior to 1.98 expose sensitive instance management API endpoints without authentication. Unauthenticated attackers can query endpoints like /api/v1/consolidated-api/view and /api/v1/tenants/current to retrieve configuration metadata, license information, and unsalted SHA-256 hashes of admin email domains for reconnaissance and targeted attack planning.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| appsmith | appsmith | 𝑥 < 1.98.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration