The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the attacker to change other users’ passwords if the attacker’s account has Edit users permission (which doesn’t allow changing others’ passwords) and lacks Administrate users permission (which is required to change others’ passwords).
History

Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the attacker to change other users’ passwords if the attacker’s account has Edit users permission (which doesn’t allow changing others’ passwords) and lacks Administrate users permission (which is required to change others’ passwords).
Title Arbitrary user password reset leading to administrator account takeover
First Time appeared Craftcms
Craftcms cms
Weaknesses CWE-285
CPEs cpe:2.3:a:craftcms:cms:*:*:*:*:*:*:*:*
Vendors & Products Craftcms
Craftcms cms
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Hackrate

Published: 2026-09-02T14:11:02.784Z

Updated: 2026-09-02T17:51:42.963Z

Reserved: 2026-08-25T16:39:03.171Z

Link: CVE-2026-79989

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-02T15:17:42.297

Modified: 2026-09-09T15:41:24.427

Link: CVE-2026-79989

cve-icon Redhat

No data.