A vulnerability categorized as critical has been discovered in Craft CMS up to 5.10.7 . Affected by this vulnerability is the function Save of the file ElementsController.php of the component User . Such manipulation of the argument newPassword leads to permission issues. This vulnerability is referenced as CVE-2026-72786 . It is possible to launch the attack remotely. No exploit is available. It is advisable to upgrade the affected component.