SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-79989

HIGH · CVSS 8.7 EPSS 0.31% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Authenticated users can exploit this vulnerability to change their own passwords without needing to provide the current password, and those with specific permissions can also alter other users' passwords. The impact is significant, as it undermines user account security and could lead to unauthorized access. Organizations with systems that allow user management should prioritize addressing this vulnerability to prevent potential account takeovers.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-79989
Severity
HIGH
CVSS
8.7
EPSS
0.31%

Original NVD Description

The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the attacker to change other users’ passwords if the attacker’s account has Edit users permission (which doesn’t allow changing others’ passwords) and lacks Administrate users permission (which is required to change others’ passwords).