User Enumeration Vulnerability in Statamic CMS by Statamic
CVE-2026-64664
4.3MEDIUM
What is CVE-2026-64664?
An issue in Statamic CMS allowed authenticated Control Panel users to exploit an endpoint meant for the user creation wizard. This vulnerability permitted users to check whether specific email addresses were associated with existing accounts, without requiring the necessary permissions to view user data. Though this endpoint only revealed the existence of users, it posed a significant security risk by enabling potential attackers to harvest valid email addresses. Versions 5.74.1 and 6.24.0 have been released to remediate this issue.
Affected Version(s)
cms >= 6.0.0, < 6.24.0 < 6.0.0, 6.24.0
cms < 5.74.1 < 5.74.1
