CVE-2026-22794: Account Takeover Vulnerability in Appsmith
Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.93, the server uses the Origin value from the request headers as the email link baseUrl without validation. If an attacker controls the Origin, password reset / email verification links in emails can be generated pointing to the attacker’s domain, causing authentication tokens to be exposed and potentially leading to account takeover. This vulnerability is fixed in 1.93.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22794?
CVE-2026-22794 has been assessed as a high-severity account takeover vulnerability.
How do I fix CVE-2026-22794?
To fix CVE-2026-22794, upgrade Appsmith to version 1.93 or later.
What impact does CVE-2026-22794 have on users?
CVE-2026-22794 can lead to unauthorized access and control of user accounts.
Which versions of Appsmith are affected by CVE-2026-22794?
Appsmith versions prior to 1.93 are affected by CVE-2026-22794.
What type of vulnerability is CVE-2026-22794?
CVE-2026-22794 is classified as an account takeover vulnerability.