Impact
Craft CMS versions prior to 5.10.8 contain a flaw in the elements/save endpoint that permits an authenticated user with edit‑users rights to alter the newPassword field of any User element. This bypass eliminates the password verification step and gives the attacker the ability to reset any user’s password, including that of administrators. The weakness is an unauthorized access vulnerability (CWE‑285).
Affected Systems
The affected product is Craft CMS for all vendors listed as craftcms:cms. Any installation using a version earlier than 5.10.8 is vulnerable; versions 5.10.8 and later contain the fix.
Risk and Exploitability
The CVSS score of 7.1 classifies the issue as high severity. Because EPSS data is unavailable, the exact likelihood of exploitation cannot be quantified, though the vulnerability is not listed in the CISA KEV catalog. Attackers must first gain credentials that grant edit‑users permission, which can be achieved through existing compromise or privilege escalation, after which they can reset any user’s password. The impact is full account takeover and potential loss of administrative control.
OpenCVE Enrichment