Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40887

43
FAUCET Score

BRIEFING NOTE: CVE-2026-40887 OVERVIEW An unauthenticated SQL injection vulnerability exists in Vendure, an open-source headless commerce platform, affecting versions 1.7.4 through 3.6.1. A query string parameter in the Shop API is interpolated directly into raw SQL without parameterization, allowing attackers to execute arbitrary SQL commands. All supported database backends including PostgreSQL, MySQL/MariaDB, and SQLite are vulnerable. The Admin API is similarly affected but requires authentication to exploit. SEVERITY This vulnerability carries a CVSS 3.1 score of 9.1 (CRITICAL) with a network attack vector requiring no authentication, low complexity, and no user interaction. The attack has a direct impact on the application's confidentiality and availability, enabling attackers to potentially extract sensitive data and disrupt database operations. The EPSS score of 0.046 indicates this threat is more severe than over 89 percent of all published vulnerabilities. EXPLOITATION STATUS Vendure has designated this issue as requiring active mitigation with patched versions available (2.3.4, 3.5.7, and 3.6.2). While the vulnerability is not currently confirmed as actively exploited in the wild, the straightforward unauthenticated attack surface and high CVSS severity necessitate immediate patching. A temporary hotfix utilizing input validation is available for organizations unable to upgrade immediately, though parameterized query patches in official releases remain the preferred remediation approach.

Impacted Technologies

VendorProductVersion(s)CPE
VendurehqVendure
>= 1.7.4, < 2.3.4, >= 3.0.0, < 3.5.7, >= 3.6.0, < 3.6.2CNA affected

CVSS Data

CVSS version used by this source: 3.1

9.1CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.76%
Probability of exploitation in next 30 days
EPSS Percentile
75.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
Nuclei: CVE-2026-40887 · Apr 17, 2026
This CVE's current EPSS score of 0.0176 is in the 64th percentile among its peer group of 36,829 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (3)

npmpatch availablevia ghsa
Product: @vendure/coreFixed in: 3.5.7
npmpatch availablevia ghsa
Product: @vendure/coreFixed in: 3.6.2
npmpatch availablevia ghsa
Product: @vendure/coreFixed in: 2.3.4

Vendor Advisories (1)

npmGHSA-9pp3-53p2-ww9vcritical

@vendure/core has a SQL Injection vulnerability

Apr 14, 2026

References

github.com / vendurehq/vendure/security/advisories/GHSA-9pp3-53p2-ww9v