PT-2026-34036 · Unknown · Blueprintue

Published

2026-04-21

·

Updated

2026-04-21

·

CVE-2026-40588

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions blueprintUE versions prior to 4.2.0
Description The password change form at '/profile/{slug}/edit/' does not include a current password field and fails to verify the user's existing password before accepting a new one. An attacker with a valid authenticated session can change the account password without knowing the original credential, leading to permanent account takeover.
Recommendations Update to version 4.2.0.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-40588

Affected Products

Blueprintue