GHSA-225x-3jhx-wh4q: Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence
Impact
An authenticated Control Panel user could use an endpoint intended for the user creation wizard to determine if a given email address belongs to an existing user, without having permission to view users.
The endpoint only exposed user existence, not any of its data.
Patches
This has been fixed in 5.74.1 and 6.24.0.
Details
Original advisory: https://github.com/advisories/GHSA-225x-3jhx-wh4q
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-64664 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
More from GitHub Security Advisories
- mediumGHSA-957r-qf9p-67xw: Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts2026-08-06
- mediumGHSA-6hr6-w5qg-qmwg: h2: Duplicate Host header could facilitate request smuggling2026-08-06
- mediumGHSA-596p-6jv8-775v: Craft CMS: Authenticated leak of secret environment variables2026-08-06
- mediumGHSA-rvmm-v933-jgxq: Craft CMS: Missing authorization check allows non-admin control panel users access to use…2026-08-06
- lowGHSA-7hxc-f267-h5q7: Craft CMS: Incorrect path validation could potentially lead to path traversal2026-08-06