Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-34411

MEDIUM NVD
CVSS Score 5.3
Severity MEDIUM
Published Mar 27, 2026
Vendor unknown

Description

Appsmith versions prior to 1.98 expose sensitive instance management API endpoints without authentication. Unauthenticated attackers can query endpoints like /api/v1/consolidated-api/view and /api/v1/tenants/current to retrieve configuration metadata, license information, and unsalted SHA-256 hashes of admin email domains for reconnaissance and targeted attack planning.

References