THREAT OPS › Threat News › [GHSA] GHSA-225x-3jhx-wh4q (medium) — Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence
[GHSA] GHSA-225x-3jhx-wh4q (medium) — Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence
GHSA-225x-3jhx-wh4q Severity: medium CVE: CVE-2026-64664
Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence
### Impact An authenticated Control Panel user could use an endpoint intended for the user creation wizard to determine if a given email address belongs to an existing user, without having permission to view users.
The endpoint only exposed user
MITRE ATT&CK techniques
- Control PanelT1218.002
Indicators of compromise
- CVE-2026-64664cve
Original source: https://github.com/advisories/GHSA-225x-3jhx-wh4q