Junglewise Threat Intelligence

CVE-2026-79989: Craft CMS arbitrary user password reset leading to administrator account takeover

CVE-2026-79989 · Severity: info · CVSS 7.1 · Published 2026-09-02

Technologies: Craft CMS.

Executive brief

Craft CMS, a popular content management system, contains an authentication flaw that allows any logged-in user to change their own password without verification, and potentially change other users' passwords if they have user-editing permissions. An attacker with basic access or stolen credentials could escalate privileges to administrator accounts, gaining complete control over the website and its content.

Technical details

The vulnerability exists in the elements/save action during User element persistence. The UserPasswordValidator applies only a safe validator to the newPassword field without scenario restrictions, making newPassword mass-assignable during the generic element save flow and bypassing the dedicated users/set-password action that enforces elevated session verification. Any authenticated user can change their own password without providing the current password or active elevated session; users with "Edit users" permission can change any other user's password, including administrators with "Administrate users" permission. The attack requires only an active control panel session (hijacked or low-privileged) and optional Edit users permission for the privilege escalation variant. Craft CMS 5.10.8+ contains the fix; versions 5.0.0-RC1 through 5.10.7 are vulnerable.

Affected products

  • Craft CMS 5.0.0-RC1 to 5.10.7

Timeline

  • 2026-07-25: disclosed
  • 2026-08-06: advisory: Published to GitHub Advisory Database
  • 2026-07-25: patched: Fixed in Craft CMS 5.10.8

References