OAuth Email Vulnerability in Statamic CMS Versions Prior to Latest Releases
CVE-2026-64665
8.1HIGH
What is CVE-2026-64665?
Statamic is a content management system (CMS) built on Laravel and Git. In versions prior to 5.74.1 and 6.24.0, an identified flaw occurs when OAuth login is enabled with providers that do not guarantee verified email addresses. This vulnerability allows an unauthenticated attacker to log in as any existing user, potentially including super admins, solely based on matching email addresses. Consequently, exploitation can occur without requiring users' passwords, provided that OAuth is enabled with vulnerable providers. The issue has been rectified in the releases 5.74.1 and 6.24.0.
Affected Version(s)
cms < 5.74.1 < 5.74.1
cms >= 6.0.0, < 6.24.0 < 6.0.0, 6.24.0
