CVE-2026-64664 Details
Description
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could use an endpoint intended for the user creation wizard to determine if a given email address belonged to an existing user, without having permission to view users, though the endpoint only exposed user existence and not any other user data. This issue is fixed in versions 5.74.1 and 6.24.0.
A vulnerability in Statamic CMS versions prior to 5.74.1 and 6.24.0 allows authenticated Control Panel users to use an endpoint meant for the user creation wizard to check if a specific email address is associated with an existing user. This can be done without the necessary permissions to view user information. The endpoint only reveals whether the user exists, not any personal data. This issue has been addressed in versions 5.74.1 and 6.24.0.
Users can upgrade to Statamic versions 5.74.1 or 6.24.0 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 6, 2026CISA-ADP
Assessed Aug 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/statamic/cms/commit/aea68053cedab5c79d10102820b57345a7d7102e | [email protected] | Source CodeVendor |
| https://github.com/statamic/cms/pull/14905 | [email protected] | Issue TrackingVendor |
| https://github.com/statamic/cms/releases/tag/v5.74.1 | [email protected] | Release NotesVendor |
| https://github.com/statamic/cms/releases/tag/v6.24.0 | [email protected] | Release NotesVendor |
| https://github.com/statamic/cms/security/advisories/GHSA-225x-3jhx-wh4q | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Statamic | < 5.74.1 (semver) < 6.24.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 7, 2026 | CVE Modified | CISA-ADP |
| Aug 6, 2026 | New CVE Received | [email protected] |
Volerion