Description
Craft CMS versions before 5.10.11 fail to validate admin status in the actionGetPasswordResetUrl endpoint, allowing non-admin users with administrateUsers permission to mint password reset URLs for administrator accounts. Attackers can generate a valid reset URL for any admin user and set a new password via actionSetPassword, which validates only the verification code without checking the caller's session, enabling complete control-panel takeover.
Published: 2026-09-02
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Craft CMS versions before 5.10.11 allow a non‑administrator who has the administrateUsers permission to generate a password‐reset URL for any administrator account. The password‑reset endpoint accepts the request without verifying the caller’s administrative session, and the subsequent set‑password action only checks the verification code. Consequently, an attacker can set a new password for any admin account, gaining complete control of the control panel and all data it manages.

Affected Systems

The vulnerability affects Craft CMS of the craftcms:cms product line, impacting all releases from 5.0.0‑RC1 up to (but not including) 5.10.11. Users of these versions should verify their current build against the official upgrade path to 5.10.11 or later.

Risk and Exploitability

The CVSS score of 8.7 classifies this as a high‑severity flaw. Exploitation requires the attacker to possess an authenticated account with administrateUsers rights, which may be available to non‑admin users in some CMS deployments. Because the attack vector is limited to intra‑site authenticated users, the community EPSS score is listed as unavailable, but the potential impact of a successful exploit is substantial: full administrative control. The vulnerability is not currently listed in the CISA KEV catalogue, indicating that no widespread public exploits have been reported at this time.

Generated by OpenCVE AI on September 2, 2026 at 12:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Craft CMS to version 5.10.11 or later to apply the vendor patch that properly validates admin status in the password reset workflow
  • Audit and restrict the administrateUsers permission, granting it only to trusted users or deleting the role altogether if it is not needed
  • Review role assignments and ensure users with administrateUsers rights do not have other elevated privileges that could be combined with this flaw

Generated by OpenCVE AI on September 2, 2026 at 12:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description Craft CMS versions before 5.10.11 fail to validate admin status in the actionGetPasswordResetUrl endpoint, allowing non-admin users with administrateUsers permission to mint password reset URLs for administrator accounts. Attackers can generate a valid reset URL for any admin user and set a new password via actionSetPassword, which validates only the verification code without checking the caller's session, enabling complete control-panel takeover.
Title Craft CMS 5.0.0-RC1 before 5.10.11 Authentication Bypass via administrateUsers
First Time appeared Craftcms
Craftcms craft Cms
Weaknesses CWE-862
CPEs cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
Vendors & Products Craftcms
Craftcms craft Cms
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Craftcms Craft Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-02T11:11:15.664Z

Reserved: 2026-09-02T10:19:06.331Z

Link: CVE-2026-84801

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-02T12:17:16.910

Modified: 2026-09-02T13:54:48.797

Link: CVE-2026-84801

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T13:00:13Z

Weaknesses