
CVE-2026-22794 account takeover #CVE https://t.co/P18GKfuOP3
Post summary
A tweet briefly references CVE‑2026‑22794, indicating an account takeover issue but lacking any additional context or details.
Exploit discussion active in current signal (1 latest mentions)
Recommended action window: High priority (within 72h)
NVD description
Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.93, the server uses the Origin value from the request headers as the email link baseUrl without validation. If an attacker controls the Origin, password reset / email verification links in emails can be generated pointing to the attacker’s domain, causing authentication tokens to be exposed and potentially leading to account takeover. This vulnerability is fixed in 1.93.
Priority
MEDIUM
Exploitation
NONE
PoC
YES
Patch
AVAILABLE
Momentum
STABLE
If you run products in this scope, you should treat this CVE as relevant to your environment.
| Date | Total | Labels |
|---|
| 2026-01-27 | 3 | Disclosure2PoC1 |
| 2026-01-29 | 1 | Disclosure1 |
| 2026-01-30 | 2 | Disclosure2 |
| 2026-02-07 | 1 | General1 |
| 2026-02-18 | 1 | General1 |

CVE-2026-22794 account takeover #CVE https://t.co/P18GKfuOP3
Post summary
A tweet briefly references CVE‑2026‑22794, indicating an account takeover issue but lacking any additional context or details.

‼️ CVE-2026-22794: Appsmith Password Reset Account Takeover via Origin Header Injection GitHub: https://github.com/MalikHamza7/CVE-2026-22794-POC CVSS: 9.6 Writeup: https://www.resecurity.com/blog/article/cve-2026-22794-changing-the-origin-header-to-take-over-appsmith-accounts https://t.co/kU2v4rvJkY
Post summary
The text announces CVE‑2026‑22794, provides a PoC repository and writeup, confirming the existence of exploit code, but does not report active exploitation or patches.

🚨 CVE-2026-22794 : CRITICAL ACCOUNT TAKEOVER ALERT 🚨 Appsmith A critical authentication bypass vulnerability has been disclosed in Appsmith, an open-source platform widely used to build internal business tools and admin dashboards containing highly sensitive enterprise data. Risk Severity: Critical (high exploit likelihood, public exploit available, trivial attack complexity) Impact: • Complete account takeover (including admins) • Unauthorized access to internal dashboards & sensitive data • Modification of business-critical applications and workflows • Persistent backdoors via compromised admin panels • Lateral movement within corporate environments Root Cause: CWE-20 (Improper Input Validation). Appsmith blindly trusts the client-supplied Origin HTTP header when generating password reset and email verification URLs, allowing attackers to poison links and capture valid authentication tokens. Attackers can: • Send crafted requests with malicious Origin headers • Poison password reset / verification emails • Capture valid reset tokens with a single victim click • Reset passwords and seize full account control • Maintain persistent access to internal tools Are You Affected? Vulnerable: Appsmith < 1.93 Scope: Internet-facing and internally reachable self-hosted Appsmith instances Immediate Action Required: Update: Upgrade to Appsmith 1.93+ immediately Mitigation: Strip or validate Origin headers at reverse proxy / WAF Audit: Review reset requests with abnormal Origin headers and investigate unexpected password changes Internal tools are Tier-0 assets. Treat this as an emergency fix. 🛡️ #appsmith #security #ostorlabCVE
Post summary
The text announces a critical authentication‑bypass vulnerability (CVE‑2026‑22794) in Appsmith, detailing its technical root cause, impact, and recommended patch/mitigation steps.

Appsmith の脆弱性 CVE-2026-22794 が FIX:偽のパスワード・リセット警告によるアカウント乗っ取り https://iototsecnews.jp/2026/01/23/critical-appsmith-flaw-enables-account-takeovers/ ローコード・プラットフォーム Appsmith に、ユーザー・アカウントの完全な乗っ取りを許す、深刻な脆弱性 CVE-2026-22794 が見つかりました。この問題の原因は、パスワードのリセット・リクエストの Origin ヘッダ の情報に対して、サーバが検証せずに無条件で信頼してしまう欠陥にあります。 攻撃の手順は非常にシンプルでありながら、防御が難しいという特徴があります。最初に、攻撃者は、被害者のメールアドレスを使ってパスワード・リセットをリクエストしますが、その際に通信データ内の Origin ヘッダを、自分が管理する悪意のドメインに書き換えます。 Appsmith のサーバーは、この書き換えられた情報を信じてリセット・リンクを作成するため、被害者の元に届く Appsmith からのメールには、攻撃者のサーバを指す偽のリセット・リンクが含まれてしまいます。したがって、このリンクを被害者がクリックすると、パスワードの変更に必要なリセット・トークンが攻撃者のサーバに送信されます。ご利用のチームは、ご注意ください。 #Appsmith #CVE202622794 #Vulnerability
Post summary
Appsmith CVE-2026-22794 is a serious origin‑header bypass flaw that permits account takeover via manipulated password‑reset links; no active exploitation or PoC is reported, yet detailed technical information is provided.

Appsmith Vulnerable to Account Takeover Exploit – CVE-2026-22794 https://cyberthreathub.com/appsmith-vulnerable-to-account-takeover-exploit-cve-2026-22794/ #infosec #BugBounty https://t.co/pnGjzpz0rB
Post summary
A blog post announces an account takeover vulnerability in Appsmith (CVE-2026-22794) but provides no technical, exploit, or patch details.

#VulnerabilityReport #AccountTakeover Critical Appsmith Flaw CVE-2026-22794 Allows Account Takeover https://securityonline.info/critical-appsmith-flaw-cve-2026-22794-allows-account-takeover/?utm_source=dlvr.it&utm_medium=twitter
Post summary
The tweet announces a critical flaw (CVE-2026-22794) in Appsmith that could lead to account takeover, but offers no technical details, exploit code, or mitigation information.

Appsmith の脆弱性 CVE-2026-22794 が FIX:偽のパスワード・リセット警告によるアカウント乗っ取り https://iototsecnews.jp/2026/01/23/critical-appsmith-flaw-enables-account-takeovers/ 攻撃の手順は非常にシンプルでありながら、防御が難しいという特徴があります。最初に、攻撃者は、被害者のメールアドレスを使ってパスワード・リセットをリクエストしますが、その際に通信データ内の Origin ヘッダを、自分が管理する悪意のドメインに書き換えます。 Appsmith のサーバーは、この書き換えられた情報を信じてリセット・リンクを作成するため、被害者の元に届く Appsmith からのメールには、攻撃者のサーバを指す偽のリセット・リンクが含まれてしまいます。したがって、このリンクを被害者がクリックすると、パスワードの変更に必要なリセット・トークンが攻撃者のサーバに送信されます。ご利用のチームは、ご注意ください。 #Appsmith #CVE202622794 #Vulnerability
Post summary
The article reports the discovery of CVE-2026-22794, detailing how a forged Origin header can trick Appsmith into sending a malicious password‑reset link, but it does not provide PoC code, an exploit tool, or a patch.

🚨Critical Appsmith Vulnerability Enables Account Takeover Through Origin Header Manipulation (CVE-2026-22794) 🔗 https://zerodaywire.com/article.html?slug=critical-appsmith-vulnerability-enables-account-takeover-through-origin-header-manipulation-cve-2026-22794 #cybersecurity #infosec #threatintel https://t.co/QTTW4ZuMVe
Post summary
The tweet announces a critical Appsmith vulnerability (CVE‑2026‑22794) that permits account takeover via origin header manipulation, but offers no PoC, exploit, or patch details.
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | appsmith | appsmith | - | - | - |