CVE-2026-64664

MEDIUM

Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence

Title source: cna
STIX 2.1

Description

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could use an endpoint intended for the user creation wizard to determine if a given email address belonged to an existing user, without having permission to view users, though the endpoint only exposed user existence and not any other user data. This issue is fixed in versions 5.74.1 and 6.24.0.

References (5)

Core 5

Scores

CVSS v3 4.3
EPSS 0.0025
EPSS Percentile 16.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200 CWE-862
Status published
Products (4)
statamic/cms 0 - 5.74.1Packagist
statamic/cms 6.0.0 - 6.24.0Packagist
statamic/cms < 5.74.1
statamic/cms >= 6.0.0, < 6.24.0
Published Aug 06, 2026
Tracked Since Aug 07, 2026