CVE-2026-34411: Appsmith < 1.98 Unauthenticated Instance Configuration Disclosure via Management APIs
Appsmith versions prior to 1.98 expose sensitive instance management API endpoints without authentication. Unauthenticated attackers can query endpoints like /api/v1/consolidated-api/view and /api/v1/tenants/current to retrieve configuration metadata, license information, and unsalted SHA-256 hashes of admin email domains for reconnaissance and targeted attack planning.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34411?
CVE-2026-34411 is classified as a high severity vulnerability due to the exposure of sensitive information without authentication.
How do I fix CVE-2026-34411?
To fix CVE-2026-34411, upgrade Appsmith to version 1.98 or later to ensure proper authentication for management API endpoints.
What kind of information can be exposed by CVE-2026-34411?
CVE-2026-34411 can expose sensitive instance configuration data through unauthenticated access to management APIs.
Can CVE-2026-34411 be exploited remotely?
Yes, CVE-2026-34411 can be exploited remotely by unauthenticated attackers targeting the exposed management API endpoints.
What versions of Appsmith are affected by CVE-2026-34411?
Appsmith versions prior to 1.98 are affected by CVE-2026-34411 and need to be updated to resolve the issue.