PT-2026-68770 · Statamic · Statamic
CVE-2026-64665
·
Published
2026-08-06
·
Updated
2026-08-07
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Statamic versions prior to 5.74.1
Statamic versions prior to 6.24.0
Description
When OAuth login is enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker can sign in as an existing user, including super admins, without knowing the password. This occurs because the application matches OAuth identities to accounts using only the email address.
Recommendations
Update to version 5.74.1 or newer.
Update to version 6.24.0 or newer.
Only enable OAuth with providers that guarantee verified email addresses or disable OAuth login.
Exploit
Fix
Improper Authentication
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Statamic