User Enumeration Vulnerability in Statamic CMS by Statamic
CVE-2026-44306
5.3MEDIUM
What is CVE-2026-44306?
The Statamic CMS, a content management system built on Laravel, contains a vulnerability that enables an unauthenticated attacker to perform user enumeration through the forgot password mechanism. Prior to the 5.73.21 and 6.15.0 versions, responses from this feature disclosed whether an account was registered with a given email address. This information could facilitate further credential-based attacks. The vulnerability has been addressed in later releases.
Affected Version(s)
cms < 5.73.21 < 5.73.21
cms >= 6.0.0, < 6.15.0 < 6.0.0, 6.15.0
