Description
Craft CMS versions before 5.10.8 contain an authentication bypass vulnerability in the elements/save action that allows authenticated users to change passwords without verification. Attackers with edit users permission can reset any user's password including administrators by exploiting the unprotected newPassword field in the User element save flow.
Published: 2026-08-12
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Craft CMS versions prior to 5.10.8 contain a flaw in the elements/save endpoint that permits an authenticated user with edit‑users rights to alter the newPassword field of any User element. This bypass eliminates the password verification step and gives the attacker the ability to reset any user’s password, including that of administrators. The weakness is an unauthorized access vulnerability (CWE‑285).

Affected Systems

The affected product is Craft CMS for all vendors listed as craftcms:cms. Any installation using a version earlier than 5.10.8 is vulnerable; versions 5.10.8 and later contain the fix.

Risk and Exploitability

The CVSS score of 7.1 classifies the issue as high severity. Because EPSS data is unavailable, the exact likelihood of exploitation cannot be quantified, though the vulnerability is not listed in the CISA KEV catalog. Attackers must first gain credentials that grant edit‑users permission, which can be achieved through existing compromise or privilege escalation, after which they can reset any user’s password. The impact is full account takeover and potential loss of administrative control.

Generated by OpenCVE AI on August 12, 2026 at 23:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Craft CMS to 5.10.8 or later.
  • Restrict edit‑users permission to a minimal, trusted set of accounts.
  • Audit user roles to ensure no unauthorized privilege escalation has occurred.

Generated by OpenCVE AI on August 12, 2026 at 23:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description Craft CMS versions before 5.10.8 contain an authentication bypass vulnerability in the elements/save action that allows authenticated users to change passwords without verification. Attackers with edit users permission can reset any user's password including administrators by exploiting the unprotected newPassword field in the User element save flow.
Title Craft CMS 5.0.0-RC1 before 5.10.8 Authentication Bypass via Password Reset
Weaknesses CWE-285
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-12T19:07:35.873Z

Reserved: 2026-08-10T15:10:15.963Z

Link: CVE-2026-72786

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-12T20:17:49.837

Modified: 2026-08-12T20:17:49.837

Link: CVE-2026-72786

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T23:15:03Z

Weaknesses