Executive brief
Craft CMS is a popular content management system used to build and manage websites. A vulnerability in versions before 5.10.11 allows non-administrator users with specific permissions to generate password reset links for admin accounts, then change those passwords to gain full control of the platform. This enables an attacker to take over the entire CMS and access sensitive website management functions.
Technical details
The vulnerability is a missing authorization check (CWE-862) in the actionGetPasswordResetUrl endpoint of UsersController. A non-admin user holding the administrateUsers permission can call this endpoint to generate a valid password reset URL for any user, including administrators. The root cause is the omission of an admin-status guard that exists in all other destructive sibling actions. The actionSetPassword endpoint then validates only the verification code in the reset URL with no session tie to the caller, allowing the attacker to set a new password for the admin account. No authentication or elevated session is required from the target admin. The vulnerability affects Craft CMS versions 5.0.0-RC1 through 5.10.10; version 5.10.11 includes the fix.
Affected products
- Craft CMS 5.0.0-RC1 to 5.10.10
Timeline
- 2026-08-18: disclosed: GitHub Security Advisory GHSA-6qw4-cjqw-fj72 published
- 2026-09-02: advisory: CVE-2026-84801 published on NVD
- 2026-09-02: patched: Fix available in version 5.10.11