logo

Database

Authentication mechanism absence or evasion In statamic/cms

Description

Statamic: Account takeover via OAuth email matching without email-verification check

Impact

When OAuth login is enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as an existing user — potentially including a super admin — without their password. Exploitation requires OAuth to be explicitly enabled with such a provider.

Patches

Fixed in 5.74.1 and 6.24.0.

Workarounds

Only enable OAuth with providers that guarantee verified email addresses, or disable OAuth login.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions