SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-82291

HIGH · CVSS 8.1 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

HeyForm versions prior to 3.0.0-rc.8 are vulnerable due to improper handling of the Origin header in CORS responses, which allows cross-origin requests with credentials. This flaw enables attackers to execute authenticated GraphQL queries from malicious sites, potentially compromising sensitive user data and account settings. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized access and data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82291
Severity
HIGH
CVSS
8.1
EPSS
0.30%

Original NVD Description

HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing credentials, enabling cross-origin requests with authentication. Attackers can execute authenticated GraphQL queries from malicious pages visited by logged-in users to access workspaces, projects, forms, submissions, and respondent data, or modify account settings.