THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-p8x7-9vfw-p7vc (high) — Craft CMS: Arbitrary user password reset leading to administrator account takeover

[GHSA] GHSA-p8x7-9vfw-p7vc (high) — Craft CMS: Arbitrary user password reset leading to administrator account takeover

medgithub_advisoriesPublished 2026-08-06

GHSA-p8x7-9vfw-p7vc Severity: high CVE: None

Craft CMS: Arbitrary user password reset leading to administrator account takeover

The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the attacker to change other users’ passwords if the attacker’s account has `edit users` permission (

MITRE ATT&CK techniques

Original source: https://github.com/advisories/GHSA-p8x7-9vfw-p7vc