← CVEs and Advisories

CVE-2026-40588

blueprintue/blueprintue-self-hosted-edition · Severity High (CVSS 8.1) · Discovered by Pavan Nallamothu

The password-change flow did not require the current password, so an attacker with a hijacked session could take over the account. Part of a four-issue account-takeover chain.

Summary

Authenticated password change does not verify the current password (account takeover).

References

cve.org record · GitHub Security Advisory GHSA-73f2-p9jr-m44x