User Enumeration Vulnerability in Statamic CMS by Statamic
CVE-2026-64664

4.3MEDIUM

Key Information:

Vendor

Statamic

Status
Vendor
CVE Published:
6 August 2026

What is CVE-2026-64664?

An issue in Statamic CMS allowed authenticated Control Panel users to exploit an endpoint meant for the user creation wizard. This vulnerability permitted users to check whether specific email addresses were associated with existing accounts, without requiring the necessary permissions to view user data. Though this endpoint only revealed the existence of users, it posed a significant security risk by enabling potential attackers to harvest valid email addresses. Versions 5.74.1 and 6.24.0 have been released to remediate this issue.

Affected Version(s)

cms >= 6.0.0, < 6.24.0 < 6.0.0, 6.24.0

cms < 5.74.1 < 5.74.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.