logo

Public Yet Private? Critical Appsmith Flaw Exposes Unpublished Actions (CVSS 9.4)

ID: 6b5fc029-cd0c-51ff-8952-ba493ab239c5

STIX ID: report--6b5fc029-cd0c-51ff-8952-ba493ab239c5

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-01-23

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical vulnerability (CVE-2026-24042, CVSS 9.4) in Appsmith v1.94 allows unauthenticated users to bypass publish protections and execute unpublished edit-mode actions by sending viewMode=false (or omitting it) to POST /api/v1/actions/execute, risking data leakage and unintended write operations; users are urged to upgrade to v1.95 or later.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.