CVE-2026-31381Disclosure(gainsight / assist)

LOWCVSS 5.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch gainsight assist systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An attacker can extract user email addresses (PII) exposed in base64 encoding via the state parameter in the OAuth callback URL.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-598

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • assist

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-04-15)
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
assist

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-03-20: 1Mentions · 2026-03-22: 2Mentions · 2026-04-15: 3Patch / Workaround · 2026-03-22: 1Patch / Workaround · 2026-04-15: 3Technical Details · 2026-03-20: 1Technical Details · 2026-03-22: 203-2003-2204-15
Signal classification2 categories
Disclosure
350.0%
Patch
350.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-201
Disclosure1
2026-03-222
Disclosure2
2026-04-153
Patch3
Full discourse6 posts
  • Rapid7@rapid7
    Disclosure

    🚨 Rapid7 Labs recently identified a chain of security vulns in #Gainsight Assist, an email plugin for the popular Customer Success software. CVE-2026-31381 & CVE-2026-31382 are an info. disclosure flaw and a reflected XSS vulnerability, respectively: https://r-7.co/4uG8I93 https://t.co/NTJGhLoacZ

    Post summary

    Rapid7 Labs announces two new CVEs in Gainsight Assist, detailing an info disclosure flaw and a reflected XSS vulnerability.

    0402452.2K
    123.8K followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Patch

    🔒 #CyberSecurity Defending Against Gainsight Assist Vulnerabilities: Urgent Patching for CVE-202… "Recent research by Rapid7 Labs has uncovered a security chain affecting the…" 🔗 https://securityarsenal.com/blog/defending-against-gainsight-assist-vulnerabilities-urgent-patching-for-cve-2026-31381-and-cve-2026-31382 #CyberSecurity #ThreatIntel #alertfatigue #triage #alertmonitor

    Post summary

    Rapid7 Labs has identified a Gainsight Assist vulnerability chain and emphasizes urgent patching; no PoC, exploit, or active exploitation details are provided.

    0000040
    10 followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Patch

    🔒 #CyberSecurity How to Protect Against Gainsight Assist Vulnerabilities: Patching CVE-2026-3138… "Security teams must remain vigilant regarding the software extensions integrated…" 🔗 https://securityarsenal.com/blog/how-to-protect-against-gainsight-assist-vulnerabilities-patching-cve-2026-31381-and-cve-2026-31382 #CyberSecurity #ThreatIntel #alertfatigue #triage #alertmonitor

    Post summary

    The tweet focuses on advising security teams to patch Gainsight Assist vulnerabilities CVE‑2026‑3138 and CVE‑2026‑31382, providing no evidence of exploitation or technical details.

    0000024
    10 followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Patch

    🔒 #CyberSecurity Critical Fixes for Gainsight Assist: Addressing CVE-2026-31381 & CVE-2026-31382 "Recent research by Rapid7 Labs has uncovered a security chain affecting the…" 🔗 https://securityarsenal.com/blog/critical-fixes-for-gainsight-assist-addressing-cve-2026-31381-and-cve-2026-31382 #CyberSecurity #ThreatIntel #alertfatigue #triage #alertmonitor

    Post summary

    The post announces critical security fixes for Gainsight Assist addressing CVE‑2026‑31381 and CVE‑2026‑31382, focusing on vendor remediation rather than exploitation details.

    0000041
    10 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31381 An attacker can extract user email addresses (PII) exposed in base64 encoding via the state parameter in the OAuth callback URL. https://www.cve.org/CVERecord?id=CVE-2026-31381

    Post summary

    The passage announces CVE‑2026‑31381, describing how PII can be extracted from a base64‑encoded OAuth state parameter, with no PoC, exploit, or patch details provided.

    0000079
    56.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-31381, CVE-2026-31382: Gainsight Assist Information Disclosure and Cross-Site Scripting (FIXED) Intel Report: https://ift.tt/dNzlPni

    Post summary

    The alert announces that CVE-2026-31381 and CVE-2026-31382 in Gainsight Assist have been disclosed and are now fixed, providing basic vulnerability details but no exploit code or active exploitation evidence.

    0000032
    291 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgainsightassist---

Explore more