PT-2026-68769 · Statamic · Statamic

CVE-2026-64664

·

Published

2026-08-06

·

Updated

2026-08-07

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Statamic versions prior to 5.74.1 Statamic versions prior to 6.24.0
Description An authenticated Control Panel user can determine if a specific email address belongs to an existing user by utilizing an endpoint designed for the user creation wizard. This occurs even if the user lacks the necessary permissions to view other users. The issue only exposes whether a user exists and does not reveal any other user data.
Recommendations Update to version 5.74.1. Update to version 6.24.0.

Exploit

Fix

Information Disclosure

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-64664
GHSA-225X-3JHX-WH4Q

Affected Products

Statamic