LOWVulnerability

CVE-2026-79989

The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the attacker to change other users’ passwords if the attacker’s account has Edit users permission (which doesn’t allow changing others’ passwords) and lacks Administrate users permission (which is required to change others’ passwords).

Properties

epss_score
0.00313
cve_id
CVE-2026-79989
signal_observed_at
2026-09-15T21:12:50+00:00
published_at
2026-09-02T15:17:42.297
last_modified
2026-09-09T15:41:24.427
epss_percentile
0.24135

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Improper Authorization

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-79989 — Ninja Signal Threat Intelligence | Ninja Signal