---
id: CVE-2026-72786
title: >-
  Craft CMS versions before 5.10.8 contain an authentication bypass
  vulnerability in the elements/save action that allows authenticated users to
  change passwords without verification
summary: >-
  Craft CMS versions before 5.10.8 contain an authentication bypass
  vulnerability in the elements/save action that allows authenticated users to
  change passwords without verification. Attackers with edit users permission
  can reset any user…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-285
vendor: craftcms
product: cms
affected:
  - cms >= 5.0.0-RC1 < 5.10.8
published: '2026-08-12'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:35.370'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-72786'
references:
  - url: 'https://github.com/craftcms/cms/security/advisories/GHSA-p8x7-9vfw-p7vc'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/craft-cms-rc1-before-authentication-bypass-via-password-reset
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-13T12:31:30.991398Z'
epss: 0.00462
epssPercentile: 0.38063
ingestedAt: '2026-10-08T16:52:14.714Z'
---

## Overview

Craft CMS versions before 5.10.8 contain an authentication bypass vulnerability in the elements/save action that allows authenticated users to change passwords without verification. Attackers with edit users permission can reset any user's password including administrators by exploiting the unprotected newPassword field in the User element save flow.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
