← CVEs and Advisories

CVE-2026-40587

blueprintue/blueprintue-self-hosted-edition · Severity Medium (CVSS 6.5) · Discovered by Pavan Nallamothu

Existing sessions stayed valid after a credential change, so a stolen session survived the very password reset meant to revoke it.

Summary

Active sessions are not invalidated after a password change or reset.

References

cve.org record · GitHub Security Advisory GHSA-gqpq-x62g-p4mg