{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/statamic-cms/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Statamic CMS"],"_cs_severities":["high"],"_cs_tags":["oauth","account-takeover","cms","authentication-bypass"],"_cs_type":"advisory","_cs_vendors":["Statamic"],"content_html":"\u003cp\u003eStatamic CMS versions prior to 5.74.1 and versions in the 6.0.0 through 6.23.x series are vulnerable to an account takeover flaw, tracked as CVE-2026-64665. The vulnerability resides in the OAuth authentication flow, where the application improperly associates incoming OAuth responses with local user accounts based solely on email addresses, without verifying that the email address is marked as verified by the identity provider.\u003c/p\u003e\n\u003cp\u003eIf an administrator has enabled an OAuth provider that does not mandate email verification, an attacker can register an account at the identity provider using an email address belonging to an existing Statamic user. Upon successful OAuth authentication, the Statamic application incorrectly maps the attacker's session to the existing target account, granting the attacker full access to that user's privileges, including super-administrator rights. This bypasses standard password-based authentication and two-factor authentication, significantly increasing the risk of full site compromise.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows unauthenticated attackers to hijack accounts, including highly privileged administrator accounts. Successful exploitation leads to full site administration, potentially enabling data exfiltration, backdooring the application, or modifying site content. The scope affects all Statamic deployments where OAuth is enabled with non-strictly configured third-party providers.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Statamic CMS to version 5.74.1 or 6.24.0 immediately to apply the fix for CVE-2026-64665.\u003c/li\u003e\n\u003cli\u003eReview OAuth provider configurations in the Statamic control panel and ensure that only identity providers providing verified email attributes are in use.\u003c/li\u003e\n\u003cli\u003eIf current identity providers do not guarantee email verification, disable OAuth authentication until providers with secure configurations can be implemented.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-06T21:29:58Z","date_published":"2026-08-06T21:29:58Z","id":"https://feed.craftedsignal.io/briefs/2026-08-statamic-oauth-takeover/","summary":"An unauthenticated attacker can achieve account takeover by leveraging unverified OAuth email matching in Statamic CMS, allowing unauthorized authentication as existing users including administrators.","title":"Statamic CMS Account Takeover via Unverified OAuth Email Matching","url":"https://feed.craftedsignal.io/briefs/2026-08-statamic-oauth-takeover/"}],"language":"en","title":"CraftedSignal Threat Feed - Statamic CMS","version":"https://jsonfeed.org/version/1.1"}