CVE-2026-64665High· 8.1▾ TwilightStatamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in a…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as an existing user, potentially including a super admin, without knowing that user's password, because the application matched OAuth identities to accounts by email address alone. Exploitation requires OAuth to be explicitly enabled with such a provider. This issue is fixed in versions 5.74.1 and 6.24.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
statamic/cms < 5.74.1statamic/cms >= 6.0.0, < 6.24.0Patched in:
statamic/cms 5.74.1statamic/cms 6.24.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-64664Medium· 4.3Statamic is a Laravel and Git powered content management system (CMS)
CVE-2026-64662Medium· 6.5Statamic is a Laravel and Git powered content management system (CMS)
CVE-2026-64663Medium· 6.5Statamic is a Laravel and Git powered content management system (CMS)
CVE-2026-71434Medium· 5.3Statamic is a Laravel and Git powered content management system (CMS)
CVE-2026-71435Medium· 6.1Statamic is a Laravel and Git powered content management system (CMS)
CVE-2026-49287High· 7.4Statamic CMS's unsafe method invocation via collection sorting allows data destruction