Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.7

CVE-2026-79989: Craft CMS lets logged‑in users reset passwords, risk admin takeover

CVE-2026-79989 · published 1 month ago
Summary

Craft CMS allows anyone who can log in to change their own password without needing the old one, and a user with basic edit rights can also change other accounts' passwords. This can let an attacker take over an administrator account and control the site. Apply the latest update from Craft CMS and review user permissions to ensure only trusted accounts can modify passwords.

What to do
  • Update craftcms cms to version 5.10.8 or later.
Affected software
VendorProductAffected versions
craftcms cms < 5.10.8
Original advisory text
Arbitrary user password reset leading to administrator account takeover
The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the attacker to change other users’ passwords if the attacker’s account has Edit users permission (which doesn’t allow changing others’ passwords) and lacks Administrate users permission (which is required to change others’ passwords).
Severity
8.7 High
Exploitation
<1% chance of attack within 30 days
Type
CWE-285Improper Authorization
Timeline
Published2 Sep 2026
Updated11 Oct 2026
First seen2 Sep 2026
Sources
CVE-2026-79989 · MITRE
Track software like this
Free during beta