PatchSiren cyber security CVE debrief
CVE-2026-72786 craftcms CVE debrief
CVE-2026-72786 is an authentication bypass vulnerability in Craft CMS versions before 5.10.8. The vulnerability exists in the elements/save action and allows authenticated users with edit users permission to change passwords without verification. This could lead to unauthorized password resets for any user, including administrators. Administrators and users of Craft CMS versions before 5.10.8, especially those with edit users permission, should be aware of this vulnerability and take necessary defensive actions to prevent unauthorized password resets and protect their systems. The CVE record was published on 2026-08-12T20:17:49.837Z and has not been modified since then. The NVD entry is currently Deferred.
- Vendor
- craftcms
- Product
- cms
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-12
- Original CVE updated
- 2026-08-31
- Advisory published
- 2026-08-12
- Advisory updated
- 2026-08-31
Who should care
Administrators and users of Craft CMS versions before 5.10.8, especially those with edit users permission, should be aware of this vulnerability and take necessary defensive actions to prevent unauthorized password resets and protect their systems. This includes restricting edit users permission to trusted administrators, monitoring for unauthorized password reset attempts, and implementing compensating controls for user authentication.
Technical summary
CVE-2026-72786 is an authentication bypass vulnerability in Craft CMS versions before 5.10.8. The vulnerability exists in the elements/save action and allows authenticated users with edit users permission to change passwords without verification. Attackers can exploit the unprotected newPassword field in the User element save flow to reset any user's password, including administrators. This vulnerability requires edit users permission and can be used to reset passwords without verification.
Defensive priority
CVE-2026-72786 authentication bypass vulnerability in Craft CMS versions before 5.10.8; requires edit users permission.
Recommended defensive actions
- Inventory and verify Craft CMS versions before 5.10.8
- Restrict edit users permission to trusted administrators
- Monitor for unauthorized password reset attempts
- Implement compensating controls for user authentication
- Review vendor patch guidance for Craft CMS
- Conduct exposure review for potential impact
- Track source references for updates
Evidence notes
CVE-2026-72786 authentication bypass in Craft CMS via unprotected newPassword field; vendor: Unknown Vendor; source: Vulncheck. The CVE record was published on 2026-08-12T20:17:49.837Z and has not been modified since then. The NVD entry is currently Deferred. There may be additional details in the official CVE Program record or NIST NVD detail page.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72786 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72786
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72786 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72786
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/craftcms/cms/security/advisories/GHSA-p8x7-9vfw-p7vc
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/craft-cms-rc1-before-authentication-bypass-via-password-reset
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.