Sploitus

CVE-2026-22794

3 known exploits for CVE-2026-22794

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.93, the server uses the Origin value from the request headers as the email link baseUrl without validation. If an attacker controls the Origin, password reset / email verification links in emails can be generated pointing to the attacker’s domain, causing authentication tokens to be exposed and potentially leading to account takeover. This vulnerability is fixed in 1.93.

Affected products
Appsmith
Appsmith
< 1.93
Fix
Available
CVSS 3.1
9.6 CRITICAL
EPSS
0.4% (33th percentile)
Weakness
CWE-346
NVD status
Analyzed
Published
2026-01-12
CVE-2026-22794 at NVD
Authoritative description, scoring and affected products

3 known exploits for CVE-2026-22794

Proof-of-concept code and exploit modules indexed by Sploitus