The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the attacker to change other users’ passwords if the attacker’s account has Edit users permission (which doesn’t allow changing others’ passwords) and lacks Administrate users permission (which is required to change others’ passwords).

Project Subscriptions

Vendors Products
Craftcms Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the attacker to change other users’ passwords if the attacker’s account has Edit users permission (which doesn’t allow changing others’ passwords) and lacks Administrate users permission (which is required to change others’ passwords).
Title Arbitrary user password reset leading to administrator account takeover
First Time appeared Craftcms
Craftcms cms
Weaknesses CWE-285
CPEs cpe:2.3:a:craftcms:cms:*:*:*:*:*:*:*:*
Vendors & Products Craftcms
Craftcms cms
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Hackrate

Published:

Updated: 2026-09-02T17:51:42.963Z

Reserved: 2026-08-25T16:39:03.171Z

Link: CVE-2026-79989

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-02T15:17:42.297

Modified: 2026-09-02T18:21:25.740

Link: CVE-2026-79989

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses