PT-2026-84674 · Craft Cms · Craft Cms
CVE-2026-84801
·
Published
2026-09-02
·
Updated
2026-09-03
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Craft CMS versions prior to 5.10.11
Description
Insufficient validation of administrator status in the 'actionGetPasswordResetUrl' endpoint allows non-admin users who possess the
administrateUsers permission to generate password reset URLs for administrator accounts. An attacker can use these URLs to set a new password via the 'actionSetPassword' endpoint, which only verifies the code and does not check the caller's session, potentially leading to a complete takeover of the control panel.Recommendations
Update Craft CMS to version 5.10.11 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Craft Cms