GitHub Security Advisory (GHSA-p8x7-9vfw-p7vc)Vendor advisory
https://github.com/craftcms/cms/security/advisories/GHSA-p8x7-9vfw-p7vc CVE-2026-72786
HIGH
Craft CMS 5.0.0-RC1 before 5.10.8 Authentication Bypass via Password Reset
Record summary
CVE-2026-72786 has a selected CVSS score of 7.1 (high).
Description
Craft CMS versions before 5.10.8 contain an authentication bypass vulnerability in the elements/save action that allows authenticated users to change passwords without verification. Attackers with edit users permission can reset any user's password including administrators by exploiting the unprotected newPassword field in the User element save flow.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 13, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | 5.0.0-RC1 to < 5.10.8 | affected |
| 5.10.8 | unaffected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-72786 VulnCheck Advisory: Craft CMS 5.0.0-RC1 before 5.10.8 Authentication Bypass via Password ResetThird-party advisory
https://www.vulncheck.com/advisories/craft-cms-rc1-before-authentication-bypass-via-password-reset