CVE-2026-31381: Gainsight Assist
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
An attacker can extract user email addresses (PII) exposed in base64 encoding via the state parameter in the OAuth callback URL.
Affected products
- Gainsight Assist: affected versions not specified
Published 2026-03-20. Last modified 2026-06-17.