CVE-2026-31382Patch(gainsight / assist)

LOWCVSS 6.1 · MEDIUM

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch gainsight assist systems immediately
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: High priority (within 72h)

NVD description

The error_description parameter is vulnerable to Reflected XSS. An attacker can bypass the domain's WAF using a Safari-specific onpagereveal payload.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • assist

Threat summary

  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-04-15)
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
assist

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-03-20: 1Mentions · 2026-03-22: 2Mentions · 2026-04-15: 3Exploit Tool / Code · 2026-03-22: 1Patch / Workaround · 2026-03-22: 1Patch / Workaround · 2026-04-15: 3Technical Details · 2026-03-20: 1Technical Details · 2026-03-22: 203-2003-2204-15
Signal classification2 categories
Patch
466.7%
Disclosure
233.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-201
Disclosure1
2026-03-222
Disclosure1Patch1
2026-04-153
Patch3
Full discourse6 posts
  • Rapid7@rapid7
    Disclosure

    🚨 Rapid7 Labs recently identified a chain of security vulns in #Gainsight Assist, an email plugin for the popular Customer Success software. CVE-2026-31381 & CVE-2026-31382 are an info. disclosure flaw and a reflected XSS vulnerability, respectively: https://r-7.co/4uG8I93 https://t.co/NTJGhLoacZ

    Post summary

    Rapid7 Labs disclosed two new vulnerabilities in Gainsight Assist: CVE-2026-31381 (information disclosure) and CVE-2026-31382 (reflected XSS).

    0402452.2K
    123.8K followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Patch

    🔒 #CyberSecurity Defending Against Gainsight Assist Vulnerabilities: Urgent Patching for CVE-202… "Recent research by Rapid7 Labs has uncovered a security chain affecting the…" 🔗 https://securityarsenal.com/blog/defending-against-gainsight-assist-vulnerabilities-urgent-patching-for-cve-2026-31381-and-cve-2026-31382 #CyberSecurity #ThreatIntel #alertfatigue #triage #alertmonitor

    Post summary

    The post stresses urgent patching for Gainsight Assist CVEs 2026-31381 & 31382 without providing PoC, exploit details, or evidence of active exploitation.

    0000040
    10 followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Patch

    🔒 #CyberSecurity How to Protect Against Gainsight Assist Vulnerabilities: Patching CVE-2026-3138… "Security teams must remain vigilant regarding the software extensions integrated…" 🔗 https://securityarsenal.com/blog/how-to-protect-against-gainsight-assist-vulnerabilities-patching-cve-2026-31381-and-cve-2026-31382 #CyberSecurity #ThreatIntel #alertfatigue #triage #alertmonitor

    Post summary

    The tweet promotes a blog post that discusses applying patches for the Gainsight Assist CVE‑2026‑3138 vulnerabilities, focusing on mitigation rather than attack details.

    0000024
    10 followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Patch

    🔒 #CyberSecurity Critical Fixes for Gainsight Assist: Addressing CVE-2026-31381 & CVE-2026-31382 "Recent research by Rapid7 Labs has uncovered a security chain affecting the…" 🔗 https://securityarsenal.com/blog/critical-fixes-for-gainsight-assist-addressing-cve-2026-31381-and-cve-2026-31382 #CyberSecurity #ThreatIntel #alertfatigue #triage #alertmonitor

    Post summary

    The text announces critical fixes for two CVEs in Gainsight Assist, indicating patch availability without detailing exploit tools or active exploitation.

    0000041
    10 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31382 The error_description parameter is vulnerable to Reflected XSS. An attacker can bypass the domain's WAF using a Safari-specific onpagereveal payload. https://www.cve.org/CVERecord?id=CVE-2026-31382

    Post summary

    The post discloses a Reflected XSS flaw in the error_description parameter that can be exploited via a Safari‑specific payload to bypass a domain WAF; no patch, exploitation evidence, or false‑positive assertion is provided.

    0000095
    56.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Patch

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-31381, CVE-2026-31382: Gainsight Assist Information Disclosure and Cross-Site Scripting (FIXED) Intel Report: https://ift.tt/dNzlPni

    Post summary

    Gainsight Assist’s CVE‑2026‑31381 and CVE‑2026‑31382 (information disclosure and XSS) are reported as fixed, with no evidence of active exploitation or PoC.

    0000032
    291 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgainsightassist---

Explore more