PT-2026-68770 · Statamic · Statamic

CVE-2026-64665

·

Published

2026-08-06

·

Updated

2026-08-07

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Statamic versions prior to 5.74.1 Statamic versions prior to 6.24.0
Description When OAuth login is enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker can sign in as an existing user, including super admins, without knowing the password. This occurs because the application matches OAuth identities to accounts using only the email address.
Recommendations Update to version 5.74.1 or newer. Update to version 6.24.0 or newer. Only enable OAuth with providers that guarantee verified email addresses or disable OAuth login.

Exploit

Fix

Improper Authentication

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-64665
GHSA-93QH-5269-9WCF

Affected Products

Statamic