Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40093

28
FAUCET Score

OVERVIEW CVE-2026-40093 affects nimiq-blockchain version 1.3.0 and earlier, the persistent block storage component for Nimiq's Rust blockchain implementation. The vulnerability exists in block timestamp validation logic, which fails to enforce an upper bound check against the current wall clock time. This allows malicious block-producing validators to set block timestamps arbitrarily far into the future, bypassing intended temporal constraints. SEVERITY The vulnerability carries a CVSS score of 8.1 (HIGH) with a network-based attack vector requiring low privileges and minimal complexity. While confidentiality is not impacted, the flaw enables high-integrity and high-availability attacks. The malicious timestamp manipulation directly affects critical reward calculation functions in the blockchain's reward system, enabling attackers to artificially inflate the monetary supply beyond the intended emission schedule and compromise economic parameters. EXPLOITATION STATUS There is no evidence of active exploitation in the wild. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities (KEV) catalog and remains inactive on exploit alert lists. No public exploit code is currently documented. The EPSS score of 0.00066 indicates this remains a low-probability exploitation target relative to other CVEs, though the moderate FAUCET Risk Score of 49.0 warrants attention from affected organizations.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.3.0CPE matchmatch criteria
cpe:2.3:a:nimiq:nimiq_proof-of-stake:*:*:*:*:*:rust:*:*

CVSS Data

CVSS version used by this source: 3.1

8.1HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.31%
Probability of exploitation in next 30 days
EPSS Percentile
23.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0031 is in the 11th percentile among its peer group of 17,844 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

rustGHSA-49xc-52mp-cc9jcritical

nimiq-blockchain is missing a wall-clock upper bound on block timestamps

Apr 10, 2026

References

github.com / nimiq/core-rs-albatross/security/advisories/GHSA-49xc-52mp-cc9j
Broken Link