Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-93qh-5269-9wcf | Statamic: Account takeover via OAuth email matching without email-verification check |
Fri, 07 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 07 Aug 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Statamic
Statamic cms |
|
| Vendors & Products |
Statamic
Statamic cms |
Thu, 06 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as an existing user, potentially including a super admin, without knowing that user's password, because the application matched OAuth identities to accounts by email address alone. Exploitation requires OAuth to be explicitly enabled with such a provider. This issue is fixed in versions 5.74.1 and 6.24.0. | |
| Title | Statamic: Account takeover via OAuth email matching without email-verification check | |
| Weaknesses | CWE-287 CWE-290 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-07T17:09:33.394Z
Reserved: 2026-07-20T17:11:30.897Z
Link: CVE-2026-64665
Updated: 2026-08-07T15:27:02.682Z
Status : Received
Published: 2026-08-06T22:18:14.103
Modified: 2026-08-07T18:17:20.827
Link: CVE-2026-64665
No data.
OpenCVE Enrichment
Updated: 2026-08-07T01:45:05Z
Github GHSA