GHSA-93qh-5269-9wcfHighCVSS 8.1

Statamic: Account takeover via OAuth email matching without email-verification check

Published
August 6, 2026
Last Modified
August 6, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

When OAuth login is enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as an existing user — potentially including a super admin — without their password. Exploitation requires OAuth to be explicitly enabled with such a provider.

Patches

Fixed in 5.74.1 and 6.24.0.

Workarounds

Only enable OAuth with providers that guarantee verified email addresses, or disable OAuth login.

🎯 Affected products2

  • composer/statamic/cms:< 5.74.1
  • composer/statamic/cms:>= 6.0.0, < 6.24.0

🔗 References (6)