THREAT OPS › Threat News › [GHSA] GHSA-93qh-5269-9wcf (high) — Statamic: Account takeover via OAuth email matching without email-verification check
[GHSA] GHSA-93qh-5269-9wcf (high) — Statamic: Account takeover via OAuth email matching without email-verification check
GHSA-93qh-5269-9wcf Severity: high CVE: CVE-2026-64665
Statamic: Account takeover via OAuth email matching without email-verification check
### Impact
When OAuth login is enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as an existing user — potentially including a super admin — without their password. Exploitation requires OAut
MITRE ATT&CK techniques
- Email AddressesT1589.002
Indicators of compromise
- CVE-2026-64665cve
Original source: https://github.com/advisories/GHSA-93qh-5269-9wcf