PT-2026-52131 · Appsmith · Appsmith

·

CVE-2026-49979

·

Published

2026-06-05

·

Updated

2026-06-30

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Appsmith versions prior to 1.99
Description The 'POST /api/v1/admin/send-test-email' endpoint allows the use of attacker-controlled smtpHost and smtpPort values to establish a raw JavaMail TCP connection. This process bypasses the WebClientUtils.IP CHECK FILTER, as that filter only applies to Spring WebClient HTTP requests. Furthermore, the API error response returns the raw MailException.getMessage() verbatim, which allows for error-based internal port scanning and service banner enumeration.
Recommendations Update to version 1.99. Restrict access to the 'POST /api/v1/admin/send-test-email' endpoint to minimize the risk of exploitation.

Exploit

Fix

SSRF

Generation of Error Message Containing Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-APPSMITH-2026-49979
BIT-APPSMITH-2026-7299
CVE-2026-49979
GHSA-VVXF-F8Q9-86GH

Affected Products

Appsmith