CVE-2026-84801 | Craft CMS up to 5.10.10 ActionGetPasswordResetUrl privileges management

SecurityVulns

A vulnerability labeled as critical has been found in Craft CMS up to 5.10.10. This issue affects some unknown processing of the component ActionGetPasswordResetUrl. Such manipulation leads to improper privilege management.

This vulnerability is uniquely identified as CVE-2026-84801. The attack can be launched remotely. No exploit exists.

The affected component should be upgraded.VulDB Recent EntriesRead More