CVE-2026-22794Disclosure(appsmith / appsmith)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch appsmith appsmith systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.93, the server uses the Origin value from the request headers as the email link baseUrl without validation. If an attacker controls the Origin, password reset / email verification links in emails can be generated pointing to the attacker’s domain, causing authentication tokens to be exposed and potentially leading to account takeover. This vulnerability is fixed in 1.93.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-346

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • appsmith

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 8 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 3 mentions (2026-01-27); latest day: 1
  • 8 total mentions across 5 days

Affected systems

Vendors
Products
appsmith

Deep dive

Activity timeline8 mentions / 5d
01223Mentions · 2026-01-27: 3Mentions · 2026-01-29: 1Mentions · 2026-01-30: 2Mentions · 2026-02-07: 1Mentions · 2026-02-18: 1PoC Mentioned / Linked · 2026-01-27: 1Exploit Tool / Code · 2026-01-27: 1Patch / Workaround · 2026-01-27: 1Technical Details · 2026-01-27: 3Technical Details · 2026-01-30: 201-2701-2901-3002-0702-18
Signal classification3 categories
Disclosure
562.5%
General
225.0%
PoC
112.5%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-01-273
Disclosure2PoC1
2026-01-291
Disclosure1
2026-01-302
Disclosure2
2026-02-071
General1
2026-02-181
General1
Full discourse8 posts
  • VLadimiR@Dz10Chiheb
    General

    CVE-2026-22794 account takeover #CVE https://t.co/P18GKfuOP3

    Post summary

    A tweet briefly references CVE‑2026‑22794, indicating an account takeover issue but lacking any additional context or details.

    652062840243.3K
    431 followersView on X
  • Dark Web Informer@DarkWebInformer
    PoC

    ‼️ CVE-2026-22794: Appsmith Password Reset Account Takeover via Origin Header Injection GitHub: https://github.com/MalikHamza7/CVE-2026-22794-POC CVSS: 9.6 Writeup: https://www.resecurity.com/blog/article/cve-2026-22794-changing-the-origin-header-to-take-over-appsmith-accounts https://t.co/kU2v4rvJkY

    Post summary

    The text announces CVE‑2026‑22794, provides a PoC repository and writeup, confirming the existence of exploit code, but does not report active exploitation or patches.

    02801346610.2K
    165.8K followersView on X
  • Ostorlab@OstorlabSec
    Disclosure

    🚨 CVE-2026-22794 : CRITICAL ACCOUNT TAKEOVER ALERT 🚨 Appsmith A critical authentication bypass vulnerability has been disclosed in Appsmith, an open-source platform widely used to build internal business tools and admin dashboards containing highly sensitive enterprise data. Risk Severity: Critical (high exploit likelihood, public exploit available, trivial attack complexity) Impact: • Complete account takeover (including admins) • Unauthorized access to internal dashboards & sensitive data • Modification of business-critical applications and workflows • Persistent backdoors via compromised admin panels • Lateral movement within corporate environments Root Cause: CWE-20 (Improper Input Validation). Appsmith blindly trusts the client-supplied Origin HTTP header when generating password reset and email verification URLs, allowing attackers to poison links and capture valid authentication tokens. Attackers can: • Send crafted requests with malicious Origin headers • Poison password reset / verification emails • Capture valid reset tokens with a single victim click • Reset passwords and seize full account control • Maintain persistent access to internal tools Are You Affected? Vulnerable: Appsmith < 1.93 Scope: Internet-facing and internally reachable self-hosted Appsmith instances Immediate Action Required: Update: Upgrade to Appsmith 1.93+ immediately Mitigation: Strip or validate Origin headers at reverse proxy / WAF Audit: Review reset requests with abnormal Origin headers and investigate unexpected password changes Internal tools are Tier-0 assets. Treat this as an emergency fix. 🛡️ #appsmith #security #ostorlabCVE

    Post summary

    The text announces a critical authentication‑bypass vulnerability (CVE‑2026‑22794) in Appsmith, detailing its technical root cause, impact, and recommended patch/mitigation steps.

    01031175
    582 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Appsmith の脆弱性 CVE-2026-22794 が FIX:偽のパスワード・リセット警告によるアカウント乗っ取り https://iototsecnews.jp/2026/01/23/critical-appsmith-flaw-enables-account-takeovers/ ローコード・プラットフォーム Appsmith に、ユーザー・アカウントの完全な乗っ取りを許す、深刻な脆弱性 CVE-2026-22794 が見つかりました。この問題の原因は、パスワードのリセット・リクエストの Origin ヘッダ の情報に対して、サーバが検証せずに無条件で信頼してしまう欠陥にあります。 攻撃の手順は非常にシンプルでありながら、防御が難しいという特徴があります。最初に、攻撃者は、被害者のメールアドレスを使ってパスワード・リセットをリクエストしますが、その際に通信データ内の Origin ヘッダを、自分が管理する悪意のドメインに書き換えます。 Appsmith のサーバーは、この書き換えられた情報を信じてリセット・リンクを作成するため、被害者の元に届く Appsmith からのメールには、攻撃者のサーバを指す偽のリセット・リンクが含まれてしまいます。したがって、このリンクを被害者がクリックすると、パスワードの変更に必要なリセット・トークンが攻撃者のサーバに送信されます。ご利用のチームは、ご注意ください。 #Appsmith #CVE202622794 #Vulnerability

    Post summary

    Appsmith CVE-2026-22794 is a serious origin‑header bypass flaw that permits account takeover via manipulated password‑reset links; no active exploitation or PoC is reported, yet detailed technical information is provided.

    01000160
    485 followersView on X
  • Cyber Threat Hub@CyberThreatHub
    Disclosure

    Appsmith Vulnerable to Account Takeover Exploit – CVE-2026-22794 https://cyberthreathub.com/appsmith-vulnerable-to-account-takeover-exploit-cve-2026-22794/ #infosec #BugBounty https://t.co/pnGjzpz0rB

    Post summary

    A blog post announces an account takeover vulnerability in Appsmith (CVE-2026-22794) but provides no technical, exploit, or patch details.

    00010217
    7.0K followersView on X
  • Komodo Cyber Security@Komodosec
    General

    #VulnerabilityReport #AccountTakeover Critical Appsmith Flaw CVE-2026-22794 Allows Account Takeover https://securityonline.info/critical-appsmith-flaw-cve-2026-22794-allows-account-takeover/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet announces a critical flaw (CVE-2026-22794) in Appsmith that could lead to account takeover, but offers no technical details, exploit code, or mitigation information.

    0000055
    1.5K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Appsmith の脆弱性 CVE-2026-22794 が FIX:偽のパスワード・リセット警告によるアカウント乗っ取り https://iototsecnews.jp/2026/01/23/critical-appsmith-flaw-enables-account-takeovers/ 攻撃の手順は非常にシンプルでありながら、防御が難しいという特徴があります。最初に、攻撃者は、被害者のメールアドレスを使ってパスワード・リセットをリクエストしますが、その際に通信データ内の Origin ヘッダを、自分が管理する悪意のドメインに書き換えます。 Appsmith のサーバーは、この書き換えられた情報を信じてリセット・リンクを作成するため、被害者の元に届く Appsmith からのメールには、攻撃者のサーバを指す偽のリセット・リンクが含まれてしまいます。したがって、このリンクを被害者がクリックすると、パスワードの変更に必要なリセット・トークンが攻撃者のサーバに送信されます。ご利用のチームは、ご注意ください。 #Appsmith #CVE202622794 #Vulnerability

    Post summary

    The article reports the discovery of CVE-2026-22794, detailing how a forged Origin header can trick Appsmith into sending a malicious password‑reset link, but it does not provide PoC code, an exploit tool, or a patch.

    00000117
    485 followersView on X
  • Zero Day Wire@zerodaywire
    Disclosure

    🚨Critical Appsmith Vulnerability Enables Account Takeover Through Origin Header Manipulation (CVE-2026-22794) 🔗 https://zerodaywire.com/article.html?slug=critical-appsmith-vulnerability-enables-account-takeover-through-origin-header-manipulation-cve-2026-22794 #cybersecurity #infosec #threatintel https://t.co/QTTW4ZuMVe

    Post summary

    The tweet announces a critical Appsmith vulnerability (CVE‑2026‑22794) that permits account takeover via origin header manipulation, but offers no PoC, exploit, or patch details.

    00000103
    143 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appappsmithappsmith---

Explore more