Vulnerability Description
The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the attacker to change other users’ passwords if the attacker’s account has Edit users permission (which doesn’t allow changing others’ passwords) and lacks Administrate users permission (which is required to change others’ passwords).
Related Weaknesses (CWE)
References
- https://github.com/advisories/GHSA-p8x7-9vfw-p7vc
- https://github.com/craftcms/cms
- https://github.com/craftcms/cms/releases/tag/5.10.8
- https://www.hckrt.com/hacktivity/HCKRT-ZDSZJH
FAQ
What is CVE-2026-79989?
CVE-2026-79989 is a documented vulnerability. The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the attacker to change other us...
How severe is CVE-2026-79989?
CVSS scoring is not yet available for CVE-2026-79989. Check NVD for updates.
Is there a patch for CVE-2026-79989?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.