The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the attacker to change other users’ passwords if the attacker’s account has Edit users permission (which doesn’t allow changing others’ passwords) and lacks Administrate users permission (which is required to change others’ passwords).
Metrics
Affected Vendors & Products
References
History
Wed, 02 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the attacker to change other users’ passwords if the attacker’s account has Edit users permission (which doesn’t allow changing others’ passwords) and lacks Administrate users permission (which is required to change others’ passwords). | |
| Title | Arbitrary user password reset leading to administrator account takeover | |
| First Time appeared |
Craftcms
Craftcms cms |
|
| Weaknesses | CWE-285 | |
| CPEs | cpe:2.3:a:craftcms:cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Craftcms
Craftcms cms |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Hackrate
Published: 2026-09-02T14:11:02.784Z
Updated: 2026-09-02T17:51:42.963Z
Reserved: 2026-08-25T16:39:03.171Z
Link: CVE-2026-79989
No data.
Status : Deferred
Published: 2026-09-02T15:17:42.297
Modified: 2026-09-09T15:41:24.427
Link: CVE-2026-79989
No data.