Session Management Flaw in blueprintUE by BlueprintUE
CVE-2026-40587

6.5MEDIUM

Key Information:

Vendor
CVE Published:
21 April 2026

What is CVE-2026-40587?

Prior to version 4.2.0, blueprintUE fails to invalidate user sessions after password changes or resets, allowing attackers with compromised sessions to retain access indefinitely. This is due to the design flaw in session handling where only the password is updated in the user table, leaving active sessions untouched until their configured expiry. This security oversight permits unauthorized access even after legitimate users have changed their credentials, which could potentially lead to sensitive information exposure.

Affected Version(s)

blueprintue-self-hosted-edition < 4.2.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.