OAuth Email Vulnerability in Statamic CMS Versions Prior to Latest Releases
CVE-2026-64665

8.1HIGH

Key Information:

Vendor

Statamic

Status
Vendor
CVE Published:
6 August 2026

What is CVE-2026-64665?

Statamic is a content management system (CMS) built on Laravel and Git. In versions prior to 5.74.1 and 6.24.0, an identified flaw occurs when OAuth login is enabled with providers that do not guarantee verified email addresses. This vulnerability allows an unauthenticated attacker to log in as any existing user, potentially including super admins, solely based on matching email addresses. Consequently, exploitation can occur without requiring users' passwords, provided that OAuth is enabled with vulnerable providers. The issue has been rectified in the releases 5.74.1 and 6.24.0.

Affected Version(s)

cms < 5.74.1 < 5.74.1

cms >= 6.0.0, < 6.24.0 < 6.0.0, 6.24.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.