← Vulnerability feed

Vulnerability record · CVE-2026-50189 · published 24 June 2026

CVE-2026-50189: Appsmith server-side request forgery (ssrf) vulnerability

Appsmith · Appsmith

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, Appsmith's bundled supervisord exposes an XML-RPC interface on port 9001, reachable from outside the container via a Caddy reverse-proxy route at /supervisor/* on the public ingress. Combined with the APPSMITH_SUPERVISOR_PASSWORD exposed via GET /api/v1/admin/env, any authenticated administrator can send arbitrary XML-RPC calls to supervisord and execute OS commands inside the Docker container via twiddler.addProgramToGroup. This vulnerability is fixed in 2.1.

8.9 CVSS 4.0 High EPSS 0.49% · top 60.1% CWE-183 · CWE-183CWE-918 · Server-side request forgery (SSRF)
8.9CVSS 4.0 base score
0.49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
26 Jun 2026Last modified by NVD

Description

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, Appsmith's bundled supervisord exposes an XML-RPC interface on port 9001, reachable from outside the container via a Caddy reverse-proxy route at /supervisor/* on the public ingress. Combined with the APPSMITH_SUPERVISOR_PASSWORD exposed via GET /api/v1/admin/env, any authenticated administrator can send arbitrary XML-RPC calls to supervisord and execute OS commands inside the Docker container via twiddler.addProgramToGroup. This vulnerability is fixed in 2.1.

CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-50189 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2026-55454Appsmith insecure default initialization vulnerabilityAppsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the bundled Caddy reverse-proxy's admin API — which has n…EPSS 0.60%9.8CVE-2026-24042Appsmith missing authorization vulnerabilityAppsmith is a platform to build admin panels, internal tools, and dashboards. In versions 1.94 and below, publicly accessible apps allow unauthentica…EPSS 0.65%9.8CVE-2024-55964Appsmith code injection vulnerabilityAn issue was discovered in Appsmith before 1.52. An incorrectly configured PostgreSQL instance in the Appsmith image leads to remote command executio…EPSS 6.8%9.0CVE-2026-30862Appsmith cross-site scripting vulnerabilityAppsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.96, a Critical Stored XSS vulnerability exists in the Table …EPSS 0.45%8.9CVE-2022-39824Appsmith cross-site scripting vulnerabilityServer-side JavaScript injection in Appsmith through 1.7.14 allows remote attackers to execute arbitrary JavaScript code from the server via the curr…EPSS 1.1%8.8CVE-2026-22794Appsmith origin validation error vulnerabilityAppsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.93, the server uses the Origin value from the request header…EPSS 0.39%8.8CVE-2022-38298Appsmith server-side request forgery (ssrf) vulnerabilityAppsmith v1.7.11 was discovered to allow attackers to execute an authenticated Server-Side Request Forgery (SSRF) via redirecting incoming requests t…EPSS 0.72%6.9CVE-2026-34411Appsmith missing authentication for critical function vulnerabilityAppsmith versions prior to 1.98 expose sensitive instance management API endpoints without authentication. Unauthenticated attackers can query endpoi…EPSS 0.45%

Source: NIST National Vulnerability Database (record CVE-2026-50189), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.