Medium severity4.3NVD Advisory· Published Aug 6, 2026· Updated Sep 8, 2026
CVE-2026-64664
CVE-2026-64664
Description
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could use an endpoint intended for the user creation wizard to determine if a given email address belonged to an existing user, without having permission to view users, though the endpoint only exposed user existence and not any other user data. This issue is fixed in versions 5.74.1 and 6.24.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
statamic/cmsPackagist | < 5.74.1 | 5.74.1 |
statamic/cmsPackagist | >= 6.0.0, < 6.24.0 | 6.24.0 |
Affected products
1Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-225x-3jhx-wh4qghsaADVISORY
- github.com/statamic/cms/commit/aea68053cedab5c79d10102820b57345a7d7102envdWEB
- github.com/statamic/cms/pull/14905nvdWEB
- github.com/statamic/cms/releases/tag/v5.74.1nvdWEB
- github.com/statamic/cms/releases/tag/v6.24.0nvdWEB
- github.com/statamic/cms/security/advisories/GHSA-225x-3jhx-wh4qnvdWEB
News mentions
0No linked articles in our index yet.