BRIEFING NOTE: CVE-2026-40887 OVERVIEW An unauthenticated SQL injection vulnerability exists in Vendure, an open-source headless commerce platform, affecting versions 1.7.4 through 3.6.1. A query string parameter in the Shop API is interpolated directly into raw SQL without parameterization, allowing attackers to execute arbitrary SQL commands. All supported database backends including PostgreSQL, MySQL/MariaDB, and SQLite are vulnerable. The Admin API is similarly affected but requires authentication to exploit. SEVERITY This vulnerability carries a CVSS 3.1 score of 9.1 (CRITICAL) with a network attack vector requiring no authentication, low complexity, and no user interaction. The attack has a direct impact on the application's confidentiality and availability, enabling attackers to potentially extract sensitive data and disrupt database operations. The EPSS score of 0.046 indicates this threat is more severe than over 89 percent of all published vulnerabilities. EXPLOITATION STATUS Vendure has designated this issue as requiring active mitigation with patched versions available (2.3.4, 3.5.7, and 3.6.2). While the vulnerability is not currently confirmed as actively exploited in the wild, the straightforward unauthenticated attack surface and high CVSS severity necessitate immediate patching. A temporary hotfix utilizing input validation is available for organizations unable to upgrade immediately, though parameterized query patches in official releases remain the preferred remediation approach.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Vendurehq | Vendure | >= 1.7.4, < 2.3.4, >= 3.0.0, < 3.5.7, >= 3.6.0, < 3.6.2CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.