AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-64665

HIGH · CVSS 8.1 EPSS 0.31% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Statamic CMS versions prior to 5.74.1 and 6.24.0 are vulnerable to an authentication bypass due to improper handling of OAuth logins with providers that do not verify email addresses. An unauthenticated attacker could exploit this flaw to gain access to existing user accounts, including those of super admins, by matching OAuth identities to accounts solely based on email. Organizations using affected versions with OAuth enabled should prioritize upgrading to the patched versions to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-64665
Severity
HIGH
CVSS
8.1
EPSS
0.31%

Original NVD Description

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as an existing user, potentially including a super admin, without knowing that user's password, because the application matched OAuth identities to accounts by email address alone. Exploitation requires OAuth to be explicitly enabled with such a provider. This issue is fixed in versions 5.74.1 and 6.24.0.