PT-2026-71228 · Craft Cms · Craft Cms

·

CVE-2026-72786

·

Published

2026-08-06

·

Updated

2026-08-12

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Craft CMS versions prior to 5.10.8
Description An authentication bypass exists in the 'elements/save' action. Authenticated users with permissions to edit users can reset the password of any account, including administrators, by exploiting the unprotected newPassword field within the User element save flow.
Recommendations Update to version 5.10.8 or later.

Exploit

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72786
GHSA-P8X7-9VFW-P7VC

Affected Products

Craft Cms