Description
The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the attacker to change other users’ passwords if the attacker’s account has Edit users permission (which doesn’t allow changing others’ passwords) and lacks Administrate users permission (which is required to change others’ passwords).
Published: 2026-09-02
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows any authenticated user to reset their own password without first providing the current password. Additionally, a user who has the Edit users permission, but not the Administrate users permission, can alter other users’ passwords. As a result, an attacker can take over an administrator account or otherwise elevate their privileges. The weakness is a classic case of improper access control (CWE‑285).

Affected Systems

Manufactured by Craft CMS, the vulnerability applies to all releases prior to the security update released in version 5.10.8. Any installation of Craft CMS that has not yet applied that update is potentially exploitable.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, and the EPS score is not available, so the readily exploitable likelihood is unknown but the impact is significant. Because the attack can be performed with any authenticated account that holds the Edit users permission, the barrier to exploitation is low for those users and no elevated session or admin privilege is needed. The vulnerability is not listed in CISA’s KEV catalog, but the combination of high CVSS and the ability to affect administrative credentials makes it a top‑priority concern.

Generated by OpenCVE AI on September 3, 2026 at 12:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Craft CMS to version 5.10.8 or later to apply the vendor patch.
  • Revoke the Edit users permission from non‑administrative accounts to limit password reset capabilities.
  • Invalidate existing user sessions and force all users to reset their passwords to protect against credential compromise.

Generated by OpenCVE AI on September 3, 2026 at 12:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the attacker to change other users’ passwords if the attacker’s account has Edit users permission (which doesn’t allow changing others’ passwords) and lacks Administrate users permission (which is required to change others’ passwords).
Title Arbitrary user password reset leading to administrator account takeover
First Time appeared Craftcms
Craftcms cms
Weaknesses CWE-285
CPEs cpe:2.3:a:craftcms:cms:*:*:*:*:*:*:*:*
Vendors & Products Craftcms
Craftcms cms
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Hackrate

Published:

Updated: 2026-09-02T17:51:42.963Z

Reserved: 2026-08-25T16:39:03.171Z

Link: CVE-2026-79989

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-02T15:17:42.297

Modified: 2026-09-02T18:21:25.740

Link: CVE-2026-79989

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T12:15:03Z

Weaknesses