CVE-2026-24042 is a critical vulnerability affecting Appsmith versions 1.94 and below, allowing unauthenticated users to execute unpublished actions in publicly accessible applications. This bypasses the intended publish boundary, enabling attackers to execute edit-mode queries and APIs. With a CVSS score of 9.8 (CRITICAL), the vulnerability has a low attack complexity and can lead to sensitive data exposure, development data access, and the ability to trigger side effects. There is no released fix at the time of publication, and while there are no known public exploits or active exploitation, the vulnerability has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.94CPE matchmatch criteria | cpe:2.3:a:appsmith:appsmith:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.