CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-64665

highCVSS 8.1covered by 2 sourcesfirst seen 2026-08-06
Impact When OAuth login is enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as an existing user — potentially including a super admin — without their password. Exploitation requires OAuth to be explicitly enabled with such a provider. Patches Fixed in 5.74.1 and 6.24.0. Workarounds Only enable OAuth with providers that guarantee verified email addresses, or disable OAuth login.

⚡ Watch CVE-2026-64665

Get an email if CVE-2026-64665 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (2)

External references

NVD record for CVE-2026-64665

CVE.org record

Embed the live status

CVE-2026-64665 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-64665 status](https://www.csirts.com/badge/CVE-2026-64665)](https://www.csirts.com/cve/CVE-2026-64665)