Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the attacker to change other users’ passwords if the attacker’s account has Edit users permission (which doesn’t allow changing others’ passwords) and lacks Administrate users permission (which is required to change others’ passwords). | |
| Title | Arbitrary user password reset leading to administrator account takeover | |
| First Time appeared |
Craftcms
Craftcms cms |
|
| Weaknesses | CWE-285 | |
| CPEs | cpe:2.3:a:craftcms:cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Craftcms
Craftcms cms |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Hackrate
Published:
Updated: 2026-09-02T17:51:42.963Z
Reserved: 2026-08-25T16:39:03.171Z
Link: CVE-2026-79989
No data.
Status : Received
Published: 2026-09-02T15:17:42.297
Modified: 2026-09-02T18:21:25.740
Link: CVE-2026-79989
No data.
OpenCVE Enrichment
No data.
-
CWE-285
Improper Authorization