Critical Appsmith Flaw CVE-2026-22794 Allows Account Takeover
ID: fd57ae1e-4012-5732-bd9e-92cc5b9da1e7
STIX ID: report--fd57ae1e-4012-5732-bd9e-92cc5b9da1e7
Feed Name: securityonline.info
Threat Score
A critical Appsmith vulnerability (CVE-2026-22794, CVSS 9.7) allows remote attackers to hijack user accounts by manipulating the Origin HTTP header used to construct password-reset and email-verification links; an attacker can cause reset tokens to be sent to a domain they control, enabling account takeover and data exposure. The issue affects Appsmith 1.92 and was fixed in 1.93; administrators of self-hosted instances are urged to upgrade immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
