THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-225x-3jhx-wh4q (medium) — Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence

[GHSA] GHSA-225x-3jhx-wh4q (medium) — Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence

medgithub_advisoriesPublished 2026-08-06

GHSA-225x-3jhx-wh4q Severity: medium CVE: CVE-2026-64664

Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence

### Impact An authenticated Control Panel user could use an endpoint intended for the user creation wizard to determine if a given email address belongs to an existing user, without having permission to view users.

The endpoint only exposed user

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-225x-3jhx-wh4q