VYPR
High severity8.1NVD Advisory· Published Aug 6, 2026· Updated Aug 6, 2026

Statamic: Account takeover via OAuth email matching without email-verification check

CVE-2026-64665

Description

Impact

When OAuth login is enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as an existing user — potentially including a super admin — without their password. Exploitation requires OAuth to be explicitly enabled with such a provider.

Patches

Fixed in 5.74.1 and 6.24.0.

Workarounds

Only enable OAuth with providers that guarantee verified email addresses, or disable OAuth login.

Affected products

1

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.