CVE-2026-40586Discl

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, the login form handler performs no throttling of any kind. Failed authentication attempts are processed at full network speed with no IP-based rate limiting, no per-account attempt counter, no temporary lockout, no progressive delay (Tarpit), and no CAPTCHA challenge. An attacker can submit an unlimited number of credential guesses. The password policy (10+ characters, mixed case, digit, special character) reduces the effective keyspace but does not prevent dictionary attacks, credential stuffing from breached databases, or targeted attacks against known users with predictable passwords. This vulnerability is fixed in 4.2.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-307

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Discl: 1 classified signal
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-21: 2Technical Details · 2026-04-21: 204-21
Signal classification2 categories
Discl
150.0%
Disclosure
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Discl

    🚨*CVE* CVE-2026-40586 blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, the login form handler performs no throttling of any kind. Failed authentication attempts are … https://www.cve.org/CVERecord?id=CVE-2026-40586 ----- Traducción: CVE-2026-40586 blu… http://infoflow.cloud`

    Post summary

    The post notes a missing login throttling flaw in the blueprintUE tool for Unreal Engine prior to version 4.2.0, but does not provide any PoC, exploit code, active exploitation claim, or patch information.

    0000030
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40586 blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, the login form handler performs no throttling of any kind. Failed authentication attempts are … https://www.cve.org/CVERecord?id=CVE-2026-40586

    Post summary

    The excerpt announces a vulnerability in Unreal Engine that lacks login throttling before version 4.2.0, providing basic technical detail without evidence of exploitation or mitigation.

    00000241
    57.2K followersView on X

Explore more