logo

Critical Appsmith Flaw Enables Account Takeovers

ID: ae1b49f3-a074-58d2-9d5e-a123edbfc33b

STIX ID: report--ae1b49f3-a074-58d2-9d5e-a123edbfc33b

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-01-22

Date Updated: 2026-04-22

...
...

A critical authentication vulnerability (CVE-2026-22794) in Appsmith's password-reset process allowed attackers to manipulate the Origin header to deliver reset links pointing to attacker-controlled domains, exposing reset tokens and enabling full account takeover; the issue affects Appsmith 1.92 and earlier (≈1,666 public instances) and was fixed in version 1.93.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.