Certain interaction-based devices without cooldown are vulnerable to spam/exploit attacks

Summary

Certain interaction-based devices without cooldown (e.g., buttons and item spawners) are vulnerable to spam/exploit attacks causing server lag

Please select what you are reporting on:

Unreal Editor for Fortnite

What Type of Bug are you experiencing?

Devices

Steps to Reproduce

Place interaction-based devices in a Creative/UEFN map (e.g., buttons without delay or item placer/spawner devices).
Have a player interact with the device normally to confirm it works as intended.
Use a tool or macro that allows extremely rapid interaction inputs (spam interact thousands of times per second).
Observe how the device continuously sends interaction requests to the server.
Notice performance degradation or lag affecting other devices in the map.

Expected Result

Interaction devices should include built-in rate limiting or cooldowns to prevent excessive interaction spam and maintain server stability, similar to vending machines which already implement interaction delays.

Observed Result

Devices without interaction cooldown can be spammed at extremely high frequency, generating excessive server requests. This can lead to unnecessary server load and potential lag affecting other devices and overall gameplay performance.

Platform(s)

PC / All platforms (as applicable)

Island Code

N/A

Additional Notes

This behavior can potentially be exploited by malicious users using external tools to spam interactions. It affects devices such as buttons and item placer systems, while other devices like vending machines already include built-in cooldowns that prevent this type of abuse. It would be beneficial for consistency and server protection if all interaction-based devices included similar rate limiting.

The status of FORT-1108616 changed to ‘Needs Triage’. We’ve confirmed the issue and it’s waiting to be assigned to someone to fix it.