The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the attacker to change other users’ passwords if the attacker’s account has Edit users permission (which doesn’t allow changing others’ passwords) and lacks Administrate users permission (which is required to change others’ passwords).
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 02 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the attacker to change other users’ passwords if the attacker’s account has Edit users permission (which doesn’t allow changing others’ passwords) and lacks Administrate users permission (which is required to change others’ passwords). | |
| Title | Arbitrary user password reset leading to administrator account takeover | |
| First Time appeared |
Craftcms
Craftcms cms |
|
| Weaknesses | CWE-285 | |
| CPEs | cpe:2.3:a:craftcms:cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Craftcms
Craftcms cms |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Hackrate
Published:
Updated: 2026-09-02T17:51:42.963Z
Reserved: 2026-08-25T16:39:03.171Z
Link: CVE-2026-79989
No data.
Status : Received
Published: 2026-09-02T15:17:42.297
Modified: 2026-09-02T18:21:25.740
Link: CVE-2026-79989
No data.
OpenCVE Enrichment
Updated: 2026-09-03T12:15:03Z
Weaknesses