PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72786 craftcms CVE debrief

CVE-2026-72786 is an authentication bypass vulnerability in Craft CMS versions before 5.10.8. The vulnerability exists in the elements/save action and allows authenticated users with edit users permission to change passwords without verification. This could lead to unauthorized password resets for any user, including administrators. Administrators and users of Craft CMS versions before 5.10.8, especially those with edit users permission, should be aware of this vulnerability and take necessary defensive actions to prevent unauthorized password resets and protect their systems. The CVE record was published on 2026-08-12T20:17:49.837Z and has not been modified since then. The NVD entry is currently Deferred.

Vendor
craftcms
Product
cms
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-12
Original CVE updated
2026-08-31
Advisory published
2026-08-12
Advisory updated
2026-08-31

Who should care

Administrators and users of Craft CMS versions before 5.10.8, especially those with edit users permission, should be aware of this vulnerability and take necessary defensive actions to prevent unauthorized password resets and protect their systems. This includes restricting edit users permission to trusted administrators, monitoring for unauthorized password reset attempts, and implementing compensating controls for user authentication.

Technical summary

CVE-2026-72786 is an authentication bypass vulnerability in Craft CMS versions before 5.10.8. The vulnerability exists in the elements/save action and allows authenticated users with edit users permission to change passwords without verification. Attackers can exploit the unprotected newPassword field in the User element save flow to reset any user's password, including administrators. This vulnerability requires edit users permission and can be used to reset passwords without verification.

Defensive priority

CVE-2026-72786 authentication bypass vulnerability in Craft CMS versions before 5.10.8; requires edit users permission.

Recommended defensive actions

  • Inventory and verify Craft CMS versions before 5.10.8
  • Restrict edit users permission to trusted administrators
  • Monitor for unauthorized password reset attempts
  • Implement compensating controls for user authentication
  • Review vendor patch guidance for Craft CMS
  • Conduct exposure review for potential impact
  • Track source references for updates

Evidence notes

CVE-2026-72786 authentication bypass in Craft CMS via unprotected newPassword field; vendor: Unknown Vendor; source: Vulncheck. The CVE record was published on 2026-08-12T20:17:49.837Z and has not been modified since then. The NVD entry is currently Deferred. There may be additional details in the official CVE Program record or NIST NVD detail page.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72786 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72786

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72786 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72786

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.