PT-2026-68948 · Packagist · Statamic Cms

Published

2026-08-06

·

Updated

2026-08-06

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Impact

When OAuth login is enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as an existing user — potentially including a super admin — without their password. Exploitation requires OAuth to be explicitly enabled with such a provider.

Patches

Fixed in 5.74.1 and 6.24.0.

Workarounds

Only enable OAuth with providers that guarantee verified email addresses, or disable OAuth login.

Fix

Improper Authentication

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-93QH-5269-9WCF

Affected Products

Statamic Cms