Description
Craft CMS versions before 5.10.8 contain an authentication bypass vulnerability in the elements/save action that allows authenticated users to change passwords without verification. Attackers with edit users permission can reset any user's password including administrators by exploiting the unprotected newPassword field in the User element save flow.
Published: 2026-08-12
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Craft CMS versions prior to 5.10.8 contain a flaw in the elements/save endpoint that permits an authenticated user with edit‑users rights to alter the newPassword field of any User element. This bypass eliminates the password verification step and gives the attacker the ability to reset any user’s password, including that of administrators. The weakness is an unauthorized access vulnerability (CWE‑285).

Affected Systems

The affected product is Craft CMS for all vendors listed as craftcms:cms. Any installation using a version earlier than 5.10.8 is vulnerable; versions 5.10.8 and later contain the fix.

Risk and Exploitability

The CVSS score of 7.1 classifies the issue as high severity. Because EPSS data is unavailable, the exact likelihood of exploitation cannot be quantified, though the vulnerability is not listed in the CISA KEV catalog. Attackers must first gain credentials that grant edit‑users permission, which can be achieved through existing compromise or privilege escalation, after which they can reset any user’s password. The impact is full account takeover and potential loss of administrative control.

Generated by OpenCVE AI on August 12, 2026 at 23:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Craft CMS to 5.10.8 or later.
  • Restrict edit‑users permission to a minimal, trusted set of accounts.
  • Audit user roles to ensure no unauthorized privilege escalation has occurred.

Generated by OpenCVE AI on August 12, 2026 at 23:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Craftcms craft Cms
CPEs cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
Vendors & Products Craftcms craft Cms

Thu, 13 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Craftcms
Craftcms craftcms
Vendors & Products Craftcms
Craftcms craftcms

Wed, 12 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description Craft CMS versions before 5.10.8 contain an authentication bypass vulnerability in the elements/save action that allows authenticated users to change passwords without verification. Attackers with edit users permission can reset any user's password including administrators by exploiting the unprotected newPassword field in the User element save flow.
Title Craft CMS 5.0.0-RC1 before 5.10.8 Authentication Bypass via Password Reset
Weaknesses CWE-285
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Craftcms Craft Cms Craftcms
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-14T16:51:57.728Z

Reserved: 2026-08-10T15:10:15.963Z

Link: CVE-2026-72786

cve-icon Vulnrichment

Updated: 2026-08-13T12:34:55.703Z

cve-icon NVD

Status : Deferred

Published: 2026-08-12T20:17:49.837

Modified: 2026-08-31T20:38:54.340

Link: CVE-2026-72786

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:39:16Z

Weaknesses