THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-93qh-5269-9wcf (high) — Statamic: Account takeover via OAuth email matching without email-verification check

[GHSA] GHSA-93qh-5269-9wcf (high) — Statamic: Account takeover via OAuth email matching without email-verification check

medgithub_advisoriesPublished 2026-08-06

GHSA-93qh-5269-9wcf Severity: high CVE: CVE-2026-64665

Statamic: Account takeover via OAuth email matching without email-verification check

### Impact

When OAuth login is enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as an existing user — potentially including a super admin — without their password. Exploitation requires OAut

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-93qh-5269-9wcf