Authentication Bypass in Craft CMS by Pixel & Tonic
CVE-2026-72786
7.1HIGH
What is CVE-2026-72786?
Craft CMS prior to version 5.10.8 has a vulnerability that allows authenticated users to bypass authentication when changing passwords. The flaw resides in the elements/save action, permitting users with edit permissions to reset passwords without proper validation. This situation could be exploited by attackers to modify passwords of any user, including administrative accounts, thus compromising the system's integrity and security.
Affected Version(s)
cms 5.0.0-RC1 < 5.10.8
cms 5.10.8
